flux-image

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core image-generation purpose is coherent, and the remote data flow to hosted inference apps is broadly consistent with that purpose. The main risk comes from external CLI trust and repeated transitive skill-install instructions, which expand the agent's trust boundary beyond this single skill.

Confidence: 79%Severity: 61%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:31 PM
Package URL
pkg:socket/skills-sh/inference-sh%2Fagent-skills-registry%2Fflux-image%2F@378f61f5e6d2e25d5fbeb92ff521cb55d3cc9eaf