gpt-image-gen

Warn

Audited by Socket on Jun 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior matches an OpenAI image-generation skill and uses mostly official infrastructure, but the credential-discovery scope is broader than necessary and includes reading raw local auth files. No clear malware or third-party credential-harvesting endpoint is present, but the undocumented-style Codex backend path and broad local secret access raise medium security concerns.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Jun 30, 2026, 09:22 AM
Package URL
pkg:socket/skills-sh/ninehills%2Fpublic-skills%2Fgpt-image-gen%2F@d26ded143b15bb24c183b1dcd094ff1551cec4628053fdacf5c92dd0796e18c3
Security Audit — socket — gpt-image-gen