AGENT LAB: SKILLS

image-upscaling

Fail

Audited by Socket on Feb 19, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Pipe-to-shell or eval pattern detected No explicit malicious code was found in the provided text. The main risks are supply-chain and data-exposure: executing a remote installer via curl | sh and routing images/credentials through a third-party platform (inference.sh) without documentation about retention or access controls. Treat this package as functional for its stated purpose but moderate-risk: verify installer integrity, limit credentials, and confirm the platform's privacy/security practices before use. LLM verification: The skill documentation itself is non-malicious instructional content describing use of a third-party CLI to run remote upscaling services. However, the Quick Start's use of curl | sh to install the CLI and the lack of privacy/credential handling guidance create significant supply-chain and data-exposure risks. Treat this package as suspicious from a supply-chain/privacy perspective: do not run the piped installer unverified, require signed/pinned installers or package-manager alternatives, and

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 19, 2026, 03:40 AM
Package URL
pkg:socket/skills-sh/inference-sh-3%2Fskills%2Fimage-upscaling%2F@7a1895a7127347e1d5f535739db50f807f9c5c0e