qwen-image-2-pro

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core capability matches the stated purpose, but the skill relies on a third-party gateway CLI with login, broad `belt *` execution, a pipe-to-shell installer, and extra transitive skill-install instructions. These are disclosed rather than hidden, so this is not confirmed malware, but it carries meaningful supply-chain and credential-forwarding risk.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 4, 2026, 02:26 PM
Package URL
pkg:socket/skills-sh/inferen-sh%2Fskills%2Fqwen-image-2-pro%2F@f7428b1160e9146e5f5357ebf93fc63d3cef539e
Security Audit — socket — qwen-image-2-pro