gpt-imagegen

Warn

Audited by Socket on May 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

BENIGN with medium security risk. The skill’s capabilities mostly match its stated image-generation purpose, uses local scripts, and includes sensible HTTPS/URL safety checks. The main concern is data-flow integrity: it accepts arbitrary 'OpenAI-compatible' API base URLs and forwards the API key there, and the example uses an unrelated third-party domain. That is suspicious design for credential routing but not enough to classify as malicious from the visible skill text alone.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
May 18, 2026, 03:06 AM
Package URL
pkg:socket/skills-sh/VolientDuan%2Fskills%2Fgpt-imagegen%2F@22ec160ac524b16ea624a59798bf12c85b5a578c
Security Audit — socket — gpt-imagegen