p-image

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose and data flows are mostly coherent for an image-generation skill, but risk is elevated by a custom pipe-to-shell CLI installer, broad `belt` Bash permission, credential use through that CLI, and explicit transitive skill installation. This looks more like a legitimate but higher-trust platform integration than malware.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
May 12, 2026, 06:59 PM
Package URL
pkg:socket/skills-sh/inference-sh%2Fskills%2Fp-image%2F@2e529b8daf467ee9588f5d87a1808f5228650a8a