qwen-image-2-pro

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent, but it relies on transitive skill installation, broad `infsh` CLI permissions, and credential/data routing through inference.sh rather than a direct official Alibaba integration. This looks more like a platform wrapper than a narrowly scoped model skill; concerning from a trust/scope standpoint, but not clearly malicious.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 17, 2026, 11:54 AM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Fqwen-image-2-pro%2F@33d6542244d27319cdb9f8f7f827ededb75914bc