landing-page-design
Fail
Audited by Socket on Mar 8, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
The skill's stated purpose (landing page design via AI-generated visuals and research) is coherent with its use of the inference.sh CLI. However, the footprint is not: it requires download-and-execute of an unverifiable binary from an external domain and uses third-party CLI tools to perform core functionality. This introduces supply-chain risk and potential data flow to untrusted binaries, which is disproportionate to a purely design-guidance tool. Therefore, the overall assessment is SUSPICIOUS with notable risk due to the install/execute pattern and external binaries, though not conclusively malicious without evidence of exfiltration or credential theft.
Confidence: 98%Severity: 75%
Audit Metadata