technical-blog-writing

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Verdict: SUSPICIOUS. The skill’s intended purpose (technical blog writing) is benign, but its install/execution approach (curl | sh to fetch an unverifiable binary, remote binary distribution with checksum verification, multi-domain external tooling) and data flows (credential/login surface, external API and image-generation calls) introduce non-trivial supply-chain and data-flow risks. The combination of a non-official binary installer, potential credential handling via login, and outbound content/tool interactions warrants heightened scrutiny and, unless mitigated (e.g., signing, official registries, clear per-action user consent, minimized credentials), should be treated as suspicious rather than clearly benign.

Confidence: 70%Severity: 65%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/1nfsh-s3%2Fskills%2Ftechnical-blog-writing%2F@e70bdc3e748a58a389786361a0be59666e813fa9