flux-image

Warn

Audited by Socket on May 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's image-generation behavior is broadly aligned with its purpose, but its trust chain is weaker than ideal. The main concerns are transitive skill installation, reliance on a third-party CLI for login/API handling, and mixed `belt-sh`/`inference-sh` ownership signals; these raise medium security risk without proving malicious intent.

Confidence: 81%Severity: 58%
Audit Metadata
Analyzed At
May 19, 2026, 07:51 AM
Package URL
pkg:socket/skills-sh/inference-sh%2Fskills%2Fflux-image%2F@55fae7572852ed5c9bdb3a528dbdc86f421ac699
Security Audit — socket — flux-image