Is smith-horn/skill-image-pipeline safe?
Use with caution. smith-horn/skill-image-pipeline is not clearly unsafe, but the audit flagged risks to review before you install it. Oathe's behavioral security audit gave the skill-image-pipeline skill by smith-horn a trust score of 70/100 with 3 findings (1 high).
https://github.com/smith-horn/skill-image-pipeline
Is smith-horn/skill-image-pipeline safe to install?
This skill presents itself as a legitimate image generation pipeline but exhibits concerning behavior by accessing sensitive credential files during execution. While no data exfiltration was detected, the unauthorized file access combined with a complex agent spawning architecture raises security concerns.
What security issues were found in smith-horn/skill-image-pipeline?
Category Scores
Findings (3)
HIGH Unauthorized access to sensitive credential files -75 ▶
The skill accessed multiple sensitive credential files including SSH keys, AWS credentials, Docker credentials, and environment files. While no modification or exfiltration was detected, an image generation skill has no legitimate reason to access these files.
MEDIUM Complex agent spawning architecture -40 ▶
The skill uses a complex architecture that reads agent-prompt.md and spawns a general-purpose subagent. This pattern could potentially be misused to execute arbitrary instructions beyond the stated image generation purpose.
LOW Contains executable code examples -10 ▶
The agent-prompt.md contains JavaScript code examples that could be executed by the spawned agent, including file I/O operations and API calls.
Should I install smith-horn/skill-image-pipeline?
Oathe's verdict for smith-horn/skill-image-pipeline is CAUTION with a trust score of 70/100. Recommendation: Review before install.