lov-image-creator

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core image-generation capabilities mostly match the stated purpose, and the package installs are largely official. The main issue is data-flow integrity: Gemini requests and the required API key are routed through ZenMux instead of Google's official endpoint, creating a third-party credential and content interception point. Additional medium risk comes from runtime auto-installs and remote CDN dependencies for rendering.

Confidence: 91%Severity: 74%
Audit Metadata
Analyzed At
Aug 24, 2026, 12:57 AM
Package URL
pkg:socket/skills-sh/lovstudio%2Fskills%2Flov-image-creator%2F@3af026d1603b9e339b7c95795ee24375a1398546891f61ce2991481835784f69
Security Audit — socket — lov-image-creator