imagen

Warn

Audited by Socket on Aug 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the catalog entry is mostly a redirector, not an image-generation implementation. Its main security issue is instructing installation of an upstream third-party skill from a personal GitHub source, creating transitive trust and moderate supply-chain risk without direct malicious behavior in the entry itself.

Confidence: 87%Severity: 66%
Audit Metadata
Analyzed At
Aug 2, 2026, 03:59 PM
Package URL
pkg:socket/skills-sh/hosseinmirzapur%2Fopencode-skills%2Fimagen%2F@d54db25861582e2222e9afc79574778c81d43c6bdebdc2bd61fb707e794f87ae
Security Audit — socket — imagen