gpt-image-2-seeding-image
Audited by Socket on Aug 12, 2026
2 alerts found:
AnomalySecuritySUSPICIOUS: The skill’s capabilities broadly match its stated image-generation purpose, and the only explicit dependency is a normal PyPI package. However, the actual AI Hive endpoint and the bundled script behavior are not verifiable from the provided material, so credential handling and data flow trust cannot be confirmed; this is a moderate-risk, not overtly malicious, skill.
No malicious code behavior is demonstrated in this fragment because it contains only static configuration. However, it embeds a plaintext API key and an external service base URL, creating a significant credential-leak and unauthorized-access risk if used by surrounding code or if the secret is reused elsewhere. Additional context (how this config is loaded and how requests are made) is required to assess whether the external calls are legitimate and whether the key is scoped/rotated appropriately.