product-photography

Warn

Audited by Socket on Jun 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core capability is coherent with AI product-image generation, and data flows appear to go to the expected inference.sh service. However, the skill adds unnecessary trust complexity by telling the agent to install another skill (`belt-sh/cli`) and by referencing mutable/raw install guidance; combined with official but still risky remote installer options, this makes it medium risk rather than benign.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Jun 19, 2026, 02:15 AM
Package URL
pkg:socket/skills-sh/halt-catch-fire%2Fskills%2Fproduct-photography%2F@2abf456638482cd55a22265622f7231d7a59539cf99a5b75ba18302246a51f41
Security Audit — socket — product-photography