flux-image

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core image-generation purpose is coherent, and the remote data flow to hosted inference apps is broadly consistent with that purpose. The main risk comes from external CLI trust and repeated transitive skill-install instructions, which expand the agent's trust boundary beyond this single skill.

Confidence: 79%Severity: 61%
Audit Metadata
Analyzed At
Mar 19, 2026, 01:18 PM
Package URL
pkg:socket/skills-sh/toolshell%2Fskills%2Fflux-image%2F@378f61f5e6d2e25d5fbeb92ff521cb55d3cc9eaf
Security Audit — socket — flux-image