gpt-image-2

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and data flows are mostly coherent for remote image generation, but the install/execution trust is weaker than claimed: it uses an unpinned npm CLI and the documentation overstates it as aligned with an 'official SDK' despite evidence Pilio says no official SDKs exist yet. Main risk is supply-chain and credential forwarding to the CLI, not clear malware or overt exfiltration.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
May 5, 2026, 02:16 PM
Package URL
pkg:socket/skills-sh/pilioai%2Fskills%2Fgpt-image-2%2F@1db3341661668b10f221337171c88926295017e4