Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- scripts/generate_image.js:9
Security audit
Security checks across malware telemetry and agentic risk
This skill coherently provides disclosed image-generation and local plotting tools for materials-science figures, with appropriate warnings around API keys and third-party endpoints.
Before installing, confirm you intend to use a Gemini-compatible image provider and understand that image mode sends prompts, API credentials, and selected input images to that endpoint. Prefer the official Google endpoint, use the API key file option where possible, and only enable third-party endpoints when you explicitly trust that provider.
44/44 vendors flagged this skill as clean.
Detected: suspicious.env_credential_access