lov-image-creator
Warn
Audited by Socket on Aug 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core image-generation capabilities mostly match the stated purpose, and the package installs are largely official. The main issue is data-flow integrity: Gemini requests and the required API key are routed through ZenMux instead of Google's official endpoint, creating a third-party credential and content interception point. Additional medium risk comes from runtime auto-installs and remote CDN dependencies for rendering.
Confidence: 91%Severity: 74%
Audit Metadata