flux-image
Warn
Audited by Socket on Jun 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent, and the main data flow appears aligned with inference.sh image generation, but the footprint includes transitive skill installation, broad Bash access, mutable install instructions, and some publisher/package-name ambiguity. This looks more like a medium-risk trust-chain and supply-chain issue than confirmed malicious behavior.
Confidence: 100%Severity: 60%
Audit Metadata