product-photography
Warn
Audited by Socket on May 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core capability is coherent with AI product-image generation, and data flows appear to go to the expected inference.sh service. However, the skill adds unnecessary trust complexity by telling the agent to install another skill (`belt-sh/cli`) and by referencing mutable/raw install guidance; combined with official but still risky remote installer options, this makes it medium risk rather than benign.
Confidence: 87%Severity: 58%
Audit Metadata