landing-page-design

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill's stated purpose (landing page design via AI-generated visuals and research) is coherent with its use of the inference.sh CLI. However, the footprint is not: it requires download-and-execute of an unverifiable binary from an external domain and uses third-party CLI tools to perform core functionality. This introduces supply-chain risk and potential data flow to untrusted binaries, which is disproportionate to a purely design-guidance tool. Therefore, the overall assessment is SUSPICIOUS with notable risk due to the install/execute pattern and external binaries, though not conclusively malicious without evidence of exfiltration or credential theft.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/1nfsh-s3%2Fskills%2Flanding-page-design%2F@2a69872227b9a83b20affc10933b980c68eafd1b