tuzi-image-gen

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s functionality aligns with image generation, but its default use of Tuzi as a third-party relay and its arbitrary base URL overrides create meaningful data-flow and credential-routing risk. The Bun execution path is official and not an unverifiable binary, so this is not malware, but it is a medium-risk skill due to proxy trust and endpoint override exposure.

Confidence: 88%Severity: 63%
Audit Metadata
Analyzed At
Apr 27, 2026, 12:08 AM
Package URL
pkg:socket/skills-sh/tuziapi%2Ftuzi-skills%2Ftuzi-image-gen%2F@8b6d2240bf946d8b13ea465baf13a7e1bafa03db