seo-content-brief

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill’s stated purpose (SEO content brief creation via keyword research and SERP analysis) is broadly aligned with its described methods, but the implementation relies on a curl|bash download-and-execute pattern to install an external binary and uses remote inference.sh services for core functionality. This introduces notable supply-chain and data-flow risks: unverifiable binaries, external data handling, and potential exposure of user queries. Given the combination of download-execute installation, unverifiable binary dependency, and external data flows, the skill is best characterized as SUSPICIOUS with elevated securityRisk. Recommend replacing the insecure install pattern with a verified, signed installer from official registries or bundling a verifiable CLI, and clarifying data flows and consent for outbound analytics data.

Confidence: 98%Severity: 80%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/1nfsh-s3%2Fskills%2Fseo-content-brief%2F@451e6e04499c02ba81eb32e9b2fd6af95c380fd6