gpt2api-image-generator

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's image-generation purpose is coherent, and it does not install risky tooling, but it routes prompts, images, and bearer credentials through an unofficial third-party gateway instead of official image API endpoints. That makes the main risk data-flow and credential trust, not malware or installer abuse.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Apr 28, 2026, 09:42 AM
Package URL
pkg:socket/skills-sh/acking-you%2Fcodex-bridge%2Fgpt2api-image-generator%2F@14aec6131e647d550292dec9fc09f86d8ebdad29