product-photography
Audited by Socket on Mar 7, 2026
1 alert found:
Obfuscated FileThe skill is coherently aligned with its described purpose: it leverages the inference.sh ecosystem to generate product photography assets via well-known CLI tools. The install/execution path uses standard registries and widely-used CLIs, with credentials limited to runtime CLI authentication. Data flows involve user prompts and generated media to external services, which is expected for image generation workflows. While there are typical supply-chain risks inherent to using external CLIs and API-based image generation, there is no clear evidence of credential harvesting, hidden exfiltration, or malicious behavior within the provided fragment. Overall, the footprint is benign-to-moderately suspicious due to external dependencies, but proportionate to the stated objective of AI-assisted product photography.