newsletter-curation

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s newsletter purpose is plausible, but its footprint is broader than necessary because it requires a same-org external CLI, routes work through inference.sh-managed app backends, includes social-post creation, and recommends installing additional skills. The install source appears official and documented, which lowers malware confidence, but the intermediary data flows and transitive trust chain keep overall risk at medium.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Mar 27, 2026, 02:29 PM
Package URL
pkg:socket/skills-sh/inference-sh-8%2Fskills%2Fnewsletter-curation%2F@5f6bd47976d9b38bcf4f0460a581fcbabfc55a19