tensorart-generate

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s overall behavior is coherent for an image/video generation integration, and the credential plus upload flows are broadly proportionate to that purpose. The main concerns are trust and verification: the local Python scripts are not shown, they automatically read a raw access key from a dotfile, and the documented upload path is only partially consistent with public TensorArt docs. This looks more like a legitimate but higher-trust integration than clear malware.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 21, 2026, 12:34 PM
Package URL
pkg:socket/skills-sh/Tensor-Art%2Ftensorart-skills%2Ftensorart-generate%2F@a8175a7419ec252b09f5e51d68b77aa47dde5e31