AGENT LAB: SKILLS

og-image-design

Fail

Audited by Socket on Feb 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Pipe-to-shell or eval pattern detected The artifact is documentation for an OG-image generation workflow that delegates rendering to hosted services via the infsh CLI. I found no explicit malicious code in the provided text, but there are notable supply-chain and data-exfiltration risks: executing a remote installer via `curl | sh`, broad allowed-tool privileges, and examples that transmit arbitrary HTML/prompts and require login tokens to remote services without disclosure of data handling practices. Treat the operational instructions as higher-risk: verify the installer and endpoints, avoid sending secrets, and restrict execution privileges before using. LLM verification: The SKILL.md itself contains benign examples and instructions matching its stated purpose (OG image design). However, it recommends installing and running a remote installer via curl | sh and depends on a hosted inference service (inference.sh, and third-party model endpoints). Those distribution and data-flow choices raise supply-chain and privacy concerns: executing a remote installer without verification and sending HTML/prompts and credentials to remote servers increase risk. There is no dir

Confidence: 98%Severity: 90%
Audit Metadata
Analyzed At
Feb 18, 2026, 11:16 PM
Package URL
pkg:socket/skills-sh/inference-sh-4%2Fskills%2Fog-image-design%2F@909eb763f221640bfae831b86d16b9f0c46d0687