press-release-writing

Fail

Audited by Socket on Mar 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: The core writing guidance is benign, but the skill mixes a press-release tutorial with external CLI installation, credentialed platform use, intermediary-routed research calls, wildcard Bash allowance, and transitive skill installation. Same-org evidence makes the installer more trustworthy than a random payload, so this is not malware, but the operational footprint is broader than necessary for a writing skill.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Mar 27, 2026, 02:29 PM
Package URL
pkg:socket/skills-sh/inference-sh-8%2Fskills%2Fpress-release-writing%2F@80533193815992856ef2c90b2568ce241dfe5a87