character-design-sheet

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill aims to enable character-design consistency using an external Flux LoRA workflow via a downloaded CLI. However, it embeds a download-and-execute pattern from an unfamiliar domain and relies on unverifiable binary distribution, which constitutes a notable supply-chain risk. While the intended purpose is legitimate developer tooling for art pipelines, the installation and data-flow patterns justify labeling as SUSPICIOUS with high risk due to external binary execution, potential credential handling, and data exfiltration paths. If you pursue this, ensure the binary is open-source, verifiably signed, and that data flows to trusted endpoints with clear, user-consented data governance.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/1nfsh-s3%2Fskills%2Fcharacter-design-sheet%2F@2eaca433274a596c6656aa32fb2c64258bd9b1b6