AGENT LAB: SKILLS

case-study-writing

Fail

Audited by Socket on Feb 19, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Pipe-to-shell or eval pattern detected This skill is functionally benign in content and intent: it provides templates, writing guidance, and examples that leverage a third-party CLI (inference.sh) to run searches and generate visuals. I did not find embedded malware, obfuscated payloads, or hardcoded secrets in the provided text. However, there are supply-chain and privacy risks: the recommended curl | sh installer pattern and the habit of sending customer data and quoted text to hosted inference.sh apps can expose sensitive information to third parties and amplify pipeline risk. If you plan to use this skill with real customer data, treat inference.sh as an external data processor, verify their security/privacy posture, and prefer safer installation and local-only execution options where possible. LLM verification: This SKILL.md is a legitimate documentation artifact for a case-study writing workflow that integrates a third-party CLI (infsh) and remote apps for research and visualization. The file itself contains no obfuscated or clearly malicious code, no hard-coded credentials, and no direct exfiltration routines. The primary security concerns are operational: the file recommends executing a remote shell installer via curl | sh and references remote services that would receive user prompts and potentiall

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 19, 2026, 03:40 AM
Package URL
pkg:socket/skills-sh/inference-sh-3%2Fskills%2Fcase-study-writing%2F@0713a9fc07b5d575dfbd613caff69a3f1ea5e1ea