prompt-to-image

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill footprint is broadly coherent with its stated purpose: it generates images via direct provider REST APIs (OpenAI and Gemini) using a bundled Node script, supports reference images, and integrates with downstream image workflows. The use of environment variables for API keys is standard, but there are modest security considerations around secret handling, logging, and data flow (prompts/refs) to external providers. No unverifiable binaries or obvious credential-forwarding to third-party tools are described, and no autonomous real-world actions are evident. Overall risk is moderate with minor concerns around secret management and data handling; it remains plausible as a legitimate developer tool when used with proper secret hygiene and logging discipline.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 05:54 AM
Package URL
pkg:socket/skills-sh/ericjy%2Finkframe%2Fprompt-to-image%2F@ad93a8746ee50868df0acbfc4935aa18d834bff0