jimeng-cli-text2image

Warn

Audited by Socket on Aug 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose and behaviors mostly align, but it requires installing and trusting an externally distributed, unverifiable CLI via `curl|bash`, then using that binary for authenticated account actions and prompt submission. The functionality is coherent, yet the install path and credential-forwarding model create high security risk without enough release transparency.

Confidence: 88%Severity: 84%
Audit Metadata
Analyzed At
Aug 7, 2026, 10:13 AM
Package URL
pkg:socket/skills-sh/full-aigc-skills%2Fjimeng-skills%2Fjimeng-cli-text2image%2F@b93443d60951657c5996048d3bbe0552a84b80c125fd8d189ee787dd823c06f4
Security Audit — socket — jimeng-cli-text2image