ai-content-pipeline

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Overall, the skill is coherent with its stated purpose of orchestrating AI-driven content pipelines but introduces noteworthy security risk due to the download-and-run installer from an external host (unverifiable binary), reliance on multiple external tools outside official registries, and potential supply-chain exposure. It is considered SUSPICIOUS to HIGH-RISK given the unverifiable binary and multi-tool orchestration, even though there is no explicit credential exfiltration shown in the provided content. Recommend restricting execution to trusted environments, requiring verifiable signatures or official package registries for all binaries, and adding explicit data handling/privacy disclosures and per-step user confirmations for sensitive operations before deploying in production.

Confidence: 75%Severity: 70%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/1nfsh-s3%2Fskills%2Fai-content-pipeline%2F@6b1bddf9cd0b1f38697821f4976d08380aa26334