image-uploader

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

No evidence in the provided code/docs of deliberate malicious behavior or covert exfiltration. The most significant security risks are operational: mishandling of credentials (especially GitHub tokens with write scope), permanent/public storage of images in GitHub repositories, and the optional use of a non-official CDN mirror which expands the trust surface. Mitigations: restrict token scope, avoid committing config files with secrets, prefer official CDN endpoints, and consider adding explicit safeguards (input validation, size limits, not printing secrets).

Confidence: 98%
Audit Metadata
Analyzed At
Feb 25, 2026, 09:38 AM
Package URL
pkg:socket/skills-sh/crossoverjie%2Fskills%2Fimage-uploader%2F@41b98968f5f3ae46e4436718db6b6e13b5bb46c7