image-gen

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s visible workflow matches image generation, but its real trust boundary is the external listenhub CLI. Because the skill requires an unverifiable binary and appears to auto-login and forward prompts and reference files through it, this is best classified as suspicious with high security risk rather than confirmed malware.

Confidence: 83%Severity: 82%
Audit Metadata
Analyzed At
Apr 9, 2026, 07:11 AM
Package URL
pkg:socket/skills-sh/marswaveai%2Fskills%2Fimage-gen%2F@9782006b93a01196bede2d90c0bcd42968c00da0