image-studio

Warn

Audited by Socket on Aug 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent, and its credential/file access is mostly proportionate for image generation, but data flows are less clean than stated because prompts and API keys go through a third-party gateway and an unpublished local wrapper script. This is not confirmed malware, but it carries medium risk due to hidden execution details, temp prompt storage, and indirect provider routing.

Confidence: 81%Severity: 58%
Audit Metadata
Analyzed At
Aug 18, 2026, 04:05 PM
Package URL
pkg:socket/skills-sh/spacezephyr%2Fspace-gpt-image2-design%2Fimage-studio%2F@2a754d022f76905bbe8c67d1e737c800059b5f06c665cebb80d3ab9e229bd3a2
Security Audit — socket — image-studio