ai-avatar-video

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill documentation describes a legitimate-seeming media generation workflow that relies on a third-party CLI (infsh) and hosted inference services. The primary security concern is supply-chain and exfiltration risk: the README directs users to run a curl | sh installer and to use a CLI that stores credentials and uploads media to the inference.sh service. There is no evidence of explicit malicious code or obfuscation in the provided text, but the installer pattern, custom distribution domains, and reliance on remote binaries and npm packages create a moderate supply-chain risk. Users should avoid pipe-to-shell installs, verify checksums/signatures out-of-band, and treat the infsh CLI as privileged software before granting credentials or uploading sensitive media.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 25, 2026, 05:39 PM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Fai-avatar-video%2F@93d219551f68486b4ec18697d52a39ee40e34220