flux-image

Warn

Audited by Socket on Jun 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, and the main data flow appears aligned with inference.sh image generation, but the footprint includes transitive skill installation, broad Bash access, mutable install instructions, and some publisher/package-name ambiguity. This looks more like a medium-risk trust-chain and supply-chain issue than confirmed malicious behavior.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 12, 2026, 10:28 PM
Package URL
pkg:socket/skills-sh/qu-skills%2Fskills%2Fflux-image%2F@e5fd7697a91effee070047efcabf887957ba3837fd3de98690109ce5c2766a01
Security Audit — socket — flux-image