bulkgen

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities mostly match its stated image-generation purpose, and credential scope is limited to a single API key plus optional image inputs. However, it relies on opaque bundled scripts in the local skill directory, asks users to provide a live key inline, and does not provide verifiable script provenance or explicit API endpoint transparency. This is more consistent with a moderately risky, unverifiable integration than confirmed malicious behavior.

Confidence: 80%Severity: 61%
Audit Metadata
Analyzed At
Mar 14, 2026, 09:42 AM
Package URL
pkg:socket/skills-sh/oil-oil%2Fbulkgen-skill%2Fbulkgen%2F@4b0282e8dc683fd79c3c3e8b25f97d95c3c244e2