Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThis skill provides image generation and editing capabilities using the Gemini API. While the core functionality is legitimate, it is susceptible to indirect prompt injection because it processes external image files and has the capability to write to the local filesystem. Additionally, it encourages insecure API key handling via command-line arguments.
Socket
passNo alerts
Snyk
failRisk: HIGH · No issues
Runlayer
pass1/2 files flagged
ZeroLeaks
passScore: 93/100 · 2 sections analyzed