gpt-image

Warn

Audited by Socket on Jun 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is image generation, but the skill delegates execution, authentication, and data flow to inference.sh via a separately installed CLI skill instead of using OpenAI directly. This is not clearly malicious, and the publisher relationship appears coherent, but the intermediary data path, credential forwarding, transitive skill installation, and broad `belt *` permission make the footprint larger than a narrowly scoped image skill.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
Jun 19, 2026, 02:15 AM
Package URL
pkg:socket/skills-sh/halt-catch-fire%2Fskills%2Fgpt-image%2F@e249c619322ef2f3a5c0c168203b67731523ba1beff5f6807e787b89c5946dd7
Security Audit — socket — gpt-image