gpt-image-2

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and data flows are mostly coherent for remote image generation, but the install/execution trust is weaker than claimed: it uses an unpinned npm CLI and the documentation overstates it as aligned with an 'official SDK' despite evidence Pilio says no official SDKs exist yet. Main risk is supply-chain and credential forwarding to the CLI, not clear malware or overt exfiltration.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
May 3, 2026, 05:19 AM
Package URL
pkg:socket/skills-sh/pilioai%2Fskills%2Fgpt-image-2%2F@815a18e755588ced55b8ea91a114979b6a3253fa