gpt-imagegen
Warn
Audited by Socket on May 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's image-generation behavior is mostly coherent, but its data flow is not: it encourages sending prompts, local images, and API keys to a configurable 'OpenAI-compatible' endpoint, and the documented example uses examine.com rather than OpenAI's official API domain. With no malicious payload or covert exfiltration beyond the declared API calls, this is not confirmed malware, but it is a high-risk credential-routing and data-flow integrity issue.
Confidence: 91%Severity: 83%
Audit Metadata