generate-image

Warn

Audited by Socket on May 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is coherent with image-generation APIs, and the only explicit package install is benign (`requests` from PyPI), but the skill’s core behavior depends on an unseen local script that reads API keys from a .env file and runs with broad Bash(*) permissions. Data appears intended for official providers rather than a third-party proxy, so this is not confirmed malicious, but the unverifiable local implementation and credential handling make the skill medium risk.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
May 18, 2026, 03:47 PM
Package URL
pkg:socket/skills-sh/OpenClaudia%2Fopenclaudia-skills%2Fgenerate-image%2F@fc913736591448cb8f686a9609676000401d4508
Security Audit — socket — generate-image