nb-image-generation

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose is coherent, but its trust model is weak: it requires installing a third-party CLI and forwarding a Gemini API key and image data to it without verified official provenance or transparent endpoint documentation in the provided evidence. This is not confirmed malware, but it is a high-risk credential-forwarding and supply-chain pattern for an AI agent skill.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Mar 17, 2026, 10:58 AM
Package URL
pkg:socket/skills-sh/giorgioliapakis%2Fagent-skills%2Fnb-image-generation%2F@cc4843bf34385008be808ded1649736bc26ba28b