ai-image-generation

Warn

Audited by Socket on Jun 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS due to transitive skill installation and reliance on a remote-installed external CLI that receives authentication, but not clearly malicious. The overall footprint fits an image-generation SaaS skill and uses same-org infrastructure; main concerns are supply-chain trust, mutable installer execution, and expanded trust via installing other skills.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 12, 2026, 07:38 PM
Package URL
pkg:socket/skills-sh/qu-skills%2Fskills%2Fai-image-generation%2F@770db6043e785245013740c19fa1acb87cd65c7a47c31e6d93997003e498f3a6
Security Audit — socket — ai-image-generation