image-studio

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This SKILL.md documents an image-generation orchestration that prioritizes convenience by routing all user requests through a default hosted proxy. There is no direct evidence of malware or obfuscated code in the provided file. The primary security concern is architectural: the default third-party proxy can collect prompts, images, and tokens, creating privacy and credential exposure risks and increasing supply-chain attack surface. Security-conscious users should self-host the proxy, review its code, and ensure proper secret management and logging policies. For typical users who accept the proxy operator's trust, risk is moderate; for environments requiring confidentiality or strict supply-chain controls, the default configuration is not appropriate.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 12:11 PM
Package URL
pkg:socket/skills-sh/pexoai%2Fpexo-skills%2Fimage-studio%2F@e65d8836dd302c78085c05e7cc215355dc586a11