gpt-image-2

Warn

Audited by Socket on May 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the image-editing purpose is plausible, but the default behavior routes OpenAI credentials and image data through an unrelated third-party host and encourages shell-sourced secret access. Combined with a mutable clone-and-run install path from a personal repo, the skill's trust and data-flow footprint are not proportionate to a normal OpenAI image client.

Confidence: 92%Severity: 90%
Audit Metadata
Analyzed At
May 4, 2026, 02:31 PM
Package URL
pkg:socket/skills-sh/jiangmuran%2Fclaude-image%2Fgpt-image-2%2F@682e59332db2069792d048090702be2977fae912
Security Audit — socket — gpt-image-2