ai-product-photography

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill's stated purpose (AI-driven product photography via a CLI with multiple models) is coherent with its workflow. However, the install/execution pattern (curl-based download of an unverifiable binary and remote model endpoints) introduces significant supply-chain, credential, and data-flow risks. The presence of a login flow and remote generation endpoints compounds potential data exposure concerns. Given the combination of download-execute installation from an unknown domain and data flowing to external services, the overall risk is suspicious to high, with strong justification for treating as at least MEDIUM-HIGH risk until provenance and security controls are proven (verified checksums, registry-based installation, explicit data handling policies, and minimized local credential exposure).

Confidence: 72%Severity: 62%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/1nfsh-s3%2Fskills%2Fai-product-photography%2F@de2104209eede40108a9d81153b00325a3cb25ed