background-removal

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill's stated purpose (background removal via BiRefNet using a remote CLI) is broadly consistent with the capabilities. However, there is a notable security concern with the install/execution pattern: downloading a binary from a non-official registry and executing it via a shell script, even with checksum verification, constitutes an unverifiable binary risk. This elevates the securityRisk to a suspicious posture. The data flows (image URLs to an external processing service leading to a PNG output) are expected but require clear privacy/data-retention disclosures. Overall, the skill is functionally coherent for its purpose but the installation approach and external processing introduce meaningful security considerations that merit caution.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/1nfsh-s3%2Fskills%2Fbackground-removal%2F@7698142816bcf0fd308a11bd14185f642e4b81e9