image-analyzer

Warn

Audited by Socket on May 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated image-analysis purpose is plausible, but the actual data flow is mediated entirely through Gooseworks proxy endpoints that front multiple third-party services. Reading a raw local credential file and forwarding image URLs, prompts, and extracted content through an intermediary creates medium-high security risk even without clear evidence of outright malware.

Confidence: 89%Severity: 76%
Audit Metadata
Analyzed At
May 5, 2026, 12:13 PM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Fimage-analyzer%2F@cc2aa31d66bdd315d7f805396ffc4ba8775d8682