minimax-understand-image

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The workflow describes a plausible local image-understanding setup using MiniMax MCP, but relies on a high-risk download-and-execute installer and plaintext credential handling. The overall approach introduces supply-chain and credential exposure risks, and lacks explicit security controls for installer integrity, key management, and data-in-transit protection. Treat as suspicious-to-moderate risk; implement signed installers, encrypted credential storage, and explicit TLS/IPC security details before using in production.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 03:00 AM
Package URL
pkg:socket/skills-sh/Thincher%2Fskills%2Fminimax-understand-image%2F@bc1b02b4af5b9861fbfa61080e9e54fc0429888b