llm-models

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Overall, the skill presents as a Benign capability: it provides organized access to a broad set of LLMs via a documented CLI, with a standard installation flow and model invocation pattern. The primary security concerns center on the download-and-execute installer (curl | sh) pattern, though checksum verification and use of a known distributor mitigate risk. No credentials, sensitive access, or data exfiltration mechanisms are explicitly described beyond standard login flow. In sum, the footprint is coherent with the stated purpose, but the download-and-run installer pattern warrants cautious trust in the official source.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:52 AM
Package URL
pkg:socket/skills-sh/1nfsh-s3%2Fskills%2Fllm-models%2F@7194a7cac075f8383c3de3d75d7341f57a4bb61b