generate-image

Warn

Audited by Socket on Jul 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core capability matches the stated purpose, and official Gemini/OpenAI usage looks coherent. The main risk is intentional support for arbitrary OpenAI-compatible base URLs, which can route prompts, images, and API keys through unrelated third-party gateways like api.tu-zi.com; combined with runtime dependency resolution via uv, this makes the skill medium risk rather than benign.

Confidence: 88%Severity: 61%
Audit Metadata
Analyzed At
Jul 7, 2026, 03:06 AM
Package URL
pkg:socket/skills-sh/FradSer%2Fdotclaude%2Fgenerate-image%2F@c308bacb4d613612df8498a4412a3f2f78883484170c3e2c1a3505f15d4366bc
Security Audit — socket — generate-image