tzai-architecture

Warn

Audited by Socket on Aug 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill's stated purpose matches its behavior: it delegates architecture-image generation to a local tzai-image engine. Main concerns are transitive trust and supply-chain risk from requiring installation/execution of another skill and forwarding prompts/API credentials through an unreviewed underlying engine. This looks more suspicious-than-benign from a trust perspective, but not overtly malicious from the provided file alone.

Confidence: 78%Severity: 56%
Audit Metadata
Analyzed At
Aug 13, 2026, 02:22 AM
Package URL
pkg:socket/skills-sh/kedoupi%2Ftzai-image-skill%2Ftzai-architecture%2F@588bd27a5d9525766998499df3f3bfc4af906fdf24b8a7fb3b6fb5f32c7ebc27
Security Audit — socket — tzai-architecture