qwen-image-2

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent for an inference.sh platform wrapper, but it routes model use and authentication through a third-party CLI/service instead of Alibaba directly, and it encourages transitive skill installation. This is not confirmed malware, but it carries medium risk from supply-chain trust, credential forwarding, and intermediary data flow.

Confidence: 83%Severity: 56%
Audit Metadata
Analyzed At
Mar 21, 2026, 01:40 AM
Package URL
pkg:socket/skills-sh/inference-sh%2Fagent-skills%2Fqwen-image-2%2F@fbb259d833657f081f2c246f7e34c13d5f27ea07