newsletter-curation

Fail

Audited by Socket on Mar 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The core newsletter-curation purpose mostly matches the capabilities, but the skill is broader than necessary: it grants wildcard CLI execution, fetches untrusted external content, uses a pipe-to-shell installer, and encourages installing additional skills. The installer appears same-org and officially documented, which lowers malware concern, but the combination still creates medium security risk for an AI agent skill.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
Mar 25, 2026, 01:02 AM
Package URL
pkg:socket/skills-sh/inference-sh-3%2Fskills%2Fnewsletter-curation%2F@5f6bd47976d9b38bcf4f0460a581fcbabfc55a19