gpt-image-playground

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core functionality matches an OpenAI image playground, and install sources appear legitimate, but the skill encourages risky credential handling and endpoint flexibility. The main concerns are `apiKey` in URL parameters, client-side key persistence, optional routing through arbitrary proxy URLs, and a dev proxy example that disables TLS verification.

Confidence: 91%Severity: 71%
Audit Metadata
Analyzed At
Apr 28, 2026, 12:55 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fgpt-image-playground%2F@2d0a2980988e4d11a2b6052147b0cb7f3ed7cf91