qwen-image-2

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent for an inference.sh platform wrapper, but it routes model use and authentication through a third-party CLI/service instead of Alibaba directly, and it encourages transitive skill installation. This is not confirmed malware, but it carries medium risk from supply-chain trust, credential forwarding, and intermediary data flow.

Confidence: 83%Severity: 56%
Audit Metadata
Analyzed At
Apr 14, 2026, 09:11 AM
Package URL
pkg:socket/skills-sh/inference-sh%2Fagent-skills%2Fqwen-image-2%2F@1f1cdc5f611a2e095df47410283f2c61d45cbf24