gpt-image-playground
Warn
Audited by Socket on Apr 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core functionality matches an OpenAI image playground, and install sources appear legitimate, but the skill encourages risky credential handling and endpoint flexibility. The main concerns are `apiKey` in URL parameters, client-side key persistence, optional routing through arbitrary proxy URLs, and a dev proxy example that disables TLS verification.
Confidence: 91%Severity: 71%
Audit Metadata