jimeng-cli-text2image
Warn
Audited by Socket on Aug 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s stated purpose and behaviors mostly align, but it requires installing and trusting an externally distributed, unverifiable CLI via `curl|bash`, then using that binary for authenticated account actions and prompt submission. The functionality is coherent, yet the install path and credential-forwarding model create high security risk without enough release transparency.
Confidence: 88%Severity: 84%
Audit Metadata