scenario-gpt-image
Warn
Audited by Socket on Aug 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core image-generation guidance is coherent with Scenario/OpenAI use, and data flows look aligned with official Scenario MCP usage. The main concern is the explicit transitive installation of sibling skills via `npx skills add`, which extends trust to additional remote skill content; this is a medium security risk but not confirmed malicious behavior.
Confidence: 87%Severity: 56%
Audit Metadata