hunyuan-image

Warn

Audited by Socket on Sep 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core function is coherent and mostly uses official Tencent/CloudBase components, so this is not confirmed malware. The main risk is direct handling of Tencent Cloud API secrets plus a companion third-party web app that asks users to enter the same credentials, which weakens data-flow integrity and raises credential exposure concerns.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Sep 13, 2026, 12:21 PM
Package URL
pkg:socket/skills-sh/wu529778790%2Fshenzjd-skills%2Fhunyuan-image%2F@67327a8e91541abe771c9ccd498c334b0aa7752d7c6b329ece1f53eb76834f6e
Security Audit — socket — hunyuan-image