gpt-image

Warn

Audited by Socket on May 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is image generation, but the skill delegates execution, authentication, and data flow to inference.sh via a separately installed CLI skill instead of using OpenAI directly. This is not clearly malicious, and the publisher relationship appears coherent, but the intermediary data path, credential forwarding, transitive skill installation, and broad `belt *` permission make the footprint larger than a narrowly scoped image skill.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
May 18, 2026, 02:41 PM
Package URL
pkg:socket/skills-sh/inference-sh%2Fskills%2Fgpt-image%2F@927c82bff707d4b2a222f851c99797872d21d4fe
Security Audit — socket — gpt-image