web-search

Fail

Audited by Socket on Mar 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill’s purpose broadly matches web research, but it relies on a same-org pipe-to-shell installer, routes all search/extraction and auth through inference.sh’s hosted platform instead of direct Tavily/Exa APIs, grants broad `infsh` Bash scope, and encourages transitive skill installs. This looks more like a platform wrapper than a narrow web-search skill; risk is medium, driven by supply-chain hygiene, external data handling, prompt-injection exposure, and trust-chain expansion rather than confirmed malware.

Confidence: 87%Severity: 66%
Audit Metadata
Analyzed At
Mar 25, 2026, 01:01 AM
Package URL
pkg:socket/skills-sh/inference-sh-3%2Fskills%2Fweb-search%2F@a54e16ada6bd9332b4c706e2bb1292653e2a4255