gpt-image2
Warn
Audited by Socket on Sep 8, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core behavior fits an image-generation skill, but it reads raw Codex credential files and can forward those credentials, prompts, and reference images to arbitrary OpenAI-compatible base URLs rather than official APIs only. There is no strong malware signal or installer abuse, but data-flow integrity is weakened enough to treat the skill as medium-high risk.
Confidence: 89%Severity: 68%
Audit Metadata