p-image

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose and data flows are mostly coherent for an image-generation skill, but risk is elevated by a custom pipe-to-shell CLI installer, broad `belt` Bash permission, credential use through that CLI, and explicit transitive skill installation. This looks more like a legitimate but higher-trust platform integration than malware.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 27, 2026, 01:08 AM
Package URL
pkg:socket/skills-sh/infsh-skills%2Fskills%2Fp-image%2F@7186fd3273fb96d0d0201ca1030b50b66baad8d8