sn-da-image-caption

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core purpose and capabilities are mostly coherent for image captioning and data extraction, and there is no obvious malicious installer or unrelated credential grab. However, the unseen local script handles both image uploads and API credentials, the description contradicts itself about API-key requirements, and optional SN_VISION_BASE_URL permits routing images and credentials to arbitrary non-official endpoints. Overall risk is medium due to endpoint flexibility and unverifiable script behavior, not confirmed malware.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
May 10, 2026, 02:56 PM
Package URL
pkg:socket/skills-sh/OpenSenseNova%2FSenseNova-Skills%2Fsn-da-image-caption%2F@33b65344d802ae0b454092c51ec2642acaa9ad50