mcp-tokenflux-images

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but the install and execution model is not. A TokenFlux image skill should not require an unpinned raw-GitHub installer for an unrelated CLI and then forward the API key through that tool; this creates significant supply-chain and credential-handling risk despite the official TokenFlux endpoint.

Confidence: 86%Severity: 82%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:52 PM
Package URL
pkg:socket/skills-sh/vaayne%2Fcc-plugins%2Fmcp-tokenflux-images%2F@c3e1dc472dd6bad7e231ae77a23ebd4c992ea9b9