imagen

Warn

Audited by Socket on Aug 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the catalog entry is mostly a redirector, not an image-generation implementation. Its main security issue is instructing installation of an upstream third-party skill from a personal GitHub source, creating transitive trust and moderate supply-chain risk without direct malicious behavior in the entry itself.

Confidence: 87%Severity: 66%
Audit Metadata
Analyzed At
Aug 18, 2026, 12:47 PM
Package URL
pkg:socket/skills-sh/nexu-io%2Fopen-design%2Fimagen%2F@b110d1b5d5863001e36b8fa81f27c0adbe9261912d276c06316ec45f603a58e1
Security Audit — socket — imagen