cli-gpt-image

Warn

Audited by Socket on Jun 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose broadly matches its image-generation behavior, but it relies on a custom wrapper that reuses Codex CLI OAuth tokens from ~/.codex/auth.json through an unofficial flow and an unreviewed local installer. That is disproportionate enough to raise concern about credential handling and install trust, though there is not enough evidence here to call it malicious.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 9, 2026, 05:59 AM
Package URL
pkg:socket/skills-sh/yigitkonur%2Fskill-cli-gpt-image%2Fcli-gpt-image%2F@26f5e54011d01510f0d43abb7d2636e8e44f62b8
Security Audit — socket — cli-gpt-image