gpt-image-2-seeding-image

Warn

Audited by Socket on Aug 12, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities broadly match its stated image-generation purpose, and the only explicit dependency is a normal PyPI package. However, the actual AI Hive endpoint and the bundled script behavior are not verifiable from the provided material, so credential handling and data flow trust cannot be confirmed; this is a moderate-risk, not overtly malicious, skill.

Confidence: 82%Severity: 56%
SecurityMEDIUM
resources/config.example.json

No malicious code behavior is demonstrated in this fragment because it contains only static configuration. However, it embeds a plaintext API key and an external service base URL, creating a significant credential-leak and unauthorized-access risk if used by surrounding code or if the secret is reused elsewhere. Additional context (how this config is loaded and how requests are made) is required to assess whether the external calls are legitimate and whether the key is scoped/rotated appropriately.

Confidence: 70%Severity: 70%
Audit Metadata
Analyzed At
Aug 12, 2026, 12:20 PM
Package URL
pkg:socket/skills-sh/wubin1836%2Fai-hive-agent-skills%2Fgpt-image-2-seeding-image%2F@3694e03b25a0bc59d23bd1fd321c9a2d090ac9991d0aca5424f22031aa8b508c
Security Audit — socket — gpt-image-2-seeding-image