social-media-carousel

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill aligns with its stated purpose of enabling social-media carousel design via an external CLI, but it employs a download-and-execute installation pattern from an external domain and relies on a potentially unverifiable binary. Credential handling is not clearly documented, and data flows to remote endpoints are not fully specified. These factors create elevated security risk, warranting a Suspicious rating and prompting stricter controls (e.g., avoid curl|sh installs, pin hashes, use verifiable package registries, and document explicit data-handling agreements).

Confidence: 62%Severity: 55%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/1nfsh-s3%2Fskills%2Fsocial-media-carousel%2F@ec77c129346bf003cfb0b806f4cfb40b40cc426e