image-mcp

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The workflow is superficially aligned with image generation/editing, but the core dependency is an undocumented and unverifiable `image-mcp` CLI, while available evidence suggests the official product is accessed via a hosted MCP/OAuth flow instead. That mismatch, combined with credential handling and automatic file uploads through the CLI, creates high install-trust risk and medium data-flow risk.

Confidence: 84%Severity: 81%
Audit Metadata
Analyzed At
Mar 16, 2026, 12:47 AM
Package URL
pkg:socket/skills-sh/danielgwilson%2Fimage-mcp-skills%2Fimage-mcp%2F@cbe13f44770e4eb68a1a3fc79db543d5395c3a6a