social-media-carousel
Fail
Audited by Snyk on Feb 18, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.90). Yes — both domains serve a direct shell-install endpoint (cli.inference.sh) and the skill instructs piping a remote .sh into sh (curl ... | sh) from an unverified domain, which is a high-risk distribution pattern for malware even if the project is legitimate.
Audit Metadata