image-files

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The image file listing capability is functionally sound and aligned with the intended purpose, but the credential resolution pattern—auto-fetching and potentially displaying a test API key from a remote endpoint—introduces supply-chain and data-privacy concerns. The approach warrants tighter controls: avoid auto-fetching credentials without explicit user consent, never display generated keys, perform authenticated requests with securely stored keys, and ensure TLS verification and auditable logging. In practice, treat this as SUSPICIOUS with moderate risk until mitigations are in place; adopt safer defaults and clarifications in user interactions.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 07:45 PM
Package URL
pkg:socket/skills-sh/jjenkins%2Fagent-image-skills%2Fimage-files%2F@8eb70c67dfa2dec4ba98b312a0f3555c2c2a1a19