social-media-carousel

Fail

Audited by Socket on Mar 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The stated purpose matches image-generation behavior, but the skill relies on a pipe-to-shell external CLI installer, routes authentication through that CLI, and asks the agent to install more skills. Same-domain documentation and checksums suggest a legitimate ecosystem, yet the trust footprint is larger than a simple social media design guide and not fully verifiable from the provided evidence.

Confidence: 84%Severity: 80%
Audit Metadata
Analyzed At
Mar 25, 2026, 01:01 AM
Package URL
pkg:socket/skills-sh/inference-sh-3%2Fskills%2Fsocial-media-carousel%2F@e743cc00503a76a801e7231180f17d314e22286b