minimax-understand-image

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The approach aligns with its stated goal of enabling image understanding via a local MCP server but relies on high-risk patterns (remote installer, plaintext API key placeholders, multiple mirrors). To improve security, adopt signed, verifiable installation methods, remove plaintext placeholder credentials, enforce least privilege and strong file permissions, and ensure IPC is strictly local with explicit data sanitization and minimal logging. Overall risk is moderate to high due to supply-chain and credential handling concerns.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 01:59 AM
Package URL
pkg:socket/skills-sh/thincher%2Fawsome_skills%2Fminimax-understand-image%2F@45abea392ace0f44440c4e15a123594ae9c68a0a