ai-product-photography

Warn

Audited by Socket on Jun 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core capability matches product-image generation, but the skill is not self-contained and relies on a separate CLI plus multiple transitive skill installs. Main concerns are supply-chain trust and credential/data routing through the belt/inference intermediary rather than direct model APIs; this is medium risk, not confirmed malware.

Confidence: 82%Severity: 64%
Audit Metadata
Analyzed At
Jun 19, 2026, 02:15 AM
Package URL
pkg:socket/skills-sh/halt-catch-fire%2Fskills%2Fai-product-photography%2F@1d4741eb6ea0bd074c2a3d9c79196c8a83940f206b7150a42c80b85d33347085
Security Audit — socket — ai-product-photography