wangyan-gemini-image-gen
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core image-generation purpose is coherent and the uv installer is an official same-org path, but the skill permits arbitrary API base URLs and forwards the Gemini API key and image content to that endpoint. This makes credential and data routing insufficiently constrained for a normal Gemini image skill.
Confidence: 90%Severity: 68%
Audit Metadata