ai-social-media-content
Audited by Socket on Mar 8, 2026
1 alert found:
MalwareThe skill alignment is dubious due to a central workflow that downloads and executes a remote binary via curl | sh from an unverifiable source. This pattern strongly increases supply-chain risk and data integrity concerns, especially given the lack of visible cryptographic verification or documented source auditing. The skill also encourages transitive skill installation, which expands risk surface. While the intended purpose—facilitating AI-assisted multi-platform content creation—is coherent, the implementation introduces multiple high-risk vectors (unverifiable binaries, remote execution, transitive installs) that are disproportionate to the stated goal unless mitigations are put in place (verified releases, signed checksums, pinning, internal registries, explicit consent for data flows). Overall assessment: SUSPICIOUS with potential for higher risk if mitigations are not applied.