content-repurposing
Audited by Socket on Mar 8, 2026
1 alert found:
MalwareThe skill’s stated purpose (content repurposing via an external inference CLI) is technically coherent with its described workflow. However, the footprint introduces notable security concerns: it depends on downloading and executing a binary from an external source (unverifiable binary with a download-exec pattern), and it routes data through multiple external apps. This creates supply-chain risk and potential data exposure to third-party services. Given these concerns, the skill is best classified as SUSPICIOUS with high risk due to unverifiable binary distribution and remote execution patterns, warranting careful risk mitigation (e.g., require verifiable binaries, pin to official registries, provide detailed data-flow governance).