gpt-imagegen

Warn

Audited by Socket on May 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's image-generation behavior is mostly coherent, but its data flow is not: it encourages sending prompts, local images, and API keys to a configurable 'OpenAI-compatible' endpoint, and the documented example uses examine.com rather than OpenAI's official API domain. With no malicious payload or covert exfiltration beyond the declared API calls, this is not confirmed malware, but it is a high-risk credential-routing and data-flow integrity issue.

Confidence: 91%Severity: 83%
Audit Metadata
Analyzed At
May 11, 2026, 06:13 AM
Package URL
pkg:socket/skills-sh/VolientDuan%2Fskills%2Fgpt-imagegen%2F@592cfb133c5ab10fc23f2e79ddf135ccfb356959