imagen

Warn

Audited by Socket on Jun 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. This wrapper skill is purpose-aligned and does not itself exfiltrate data, but its primary behavior is to steer the agent toward installing a third-party upstream skill from a personal GitHub repo with no visible verification controls. That transitive install pattern makes the overall entry medium risk despite otherwise coherent stated functionality.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 12, 2026, 09:22 PM
Package URL
pkg:socket/skills-sh/nexu-io%2Fopen-design%2Fimagen%2F@d54db25861582e2222e9afc79574778c81d43c6bdebdc2bd61fb707e794f87ae
Security Audit — socket — imagen