ai-podcast-creation

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is a convenience wrapper and documentation for using the inference.sh platform to create AI-generated podcasts. It is not obviously malicious (no embedded backdoor code or obfuscated payloads in the provided text). However, it carries moderate supply-chain and data-exposure risks: a pipe-to-shell installer (curl | sh), reliance on remote hosted inference services (inference.sh, dist.inference.sh, openrouter), and the implicit forwarding/storage of credentials via the CLI. Users should treat the install step and the hosted processing as sensitive — verify checksums manually, review the installer script before running, and avoid sending sensitive or private documents to hosted LLM/TTS endpoints unless the platform's privacy and retention policies are acceptable. Overall malware likelihood is low, but supply-chain and data-leak risk is moderate and warrants cautious use.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 25, 2026, 05:38 PM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Fai-podcast-creation%2F@8df5202816d8eaa20b95dbc5ae2bc8f9e9850fb6