press-release-writing

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill's stated purpose (press-release writing with research) is coherent with using an external research CLI, but the installation and execution pattern (curl | sh to install an unverifiable binary) introduces strong supply-chain risk and potential data exfiltration points. Data flows go from the user to external services via the infsh CLI, which can transmit queries and results to third-party endpoints. Given the combination of unverifiable binary distribution, external data interactions, and credential handling concerns, the overall risk profile is Suspicious-to-High, with explicit overrides pushing securityRisk into a high range. I would classify this as Suspicious due to supply-chain and data-flow concerns that are not fully mitigated by documented checksums and host verification.

Confidence: 98%Severity: 85%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/1nfsh-s3%2Fskills%2Fpress-release-writing%2F@1fc472e9a03174a2f7b69062680b3e1d55347ae6