ai-image-generation

Warn

Audited by Socket on Mar 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill aligns with its stated purpose of enabling multi-model AI image generation via the inferences.sh CLI. However, it exhibits a significant supply-chain risk due to installation via curl | sh from an unverifiable remote URL, which elevates securityRisk to high (0.75) and malware risk to moderate (0.4). Data flows to external model backends are expected for this domain, but the unverifiable installer and potential credential handling during login present notable risk. If used in practice, ensure verifiable distribution (signature/sum validation, official registry), audit login credential handling, and minimize sensitive data transmitted to external services.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 12, 2026, 07:36 AM
Package URL
pkg:socket/skills-sh/happycapy-ai%2FHappycapy-skills%2Fai-image-generation%2F@7cc1f1114255cd50dea1dbe74333d1b202377405