character-design-sheet

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This SKILL.md is a user-facing guide for generating consistent character-design art via the inference.sh CLI and LoRA workflows. The content itself does not contain obvious backdoor code or obfuscated malware, but it includes multiple supply-chain and data-exposure risks: a curl|sh installer pattern (download-and-execute), distribution from a third-party domain, and workflow steps that read local model weights and images which are likely uploaded to the remote service. Those patterns permit credential forwarding and exfiltration of local assets if the CLI or remote service is malicious or compromised. Recommended mitigations: avoid pipe-to-shell installs (manually verify checksums and inspect installer), prefer OS package managers or reproducible install artifacts, verify CLI source code, audit what infsh login stores and where, avoid uploading sensitive LoRA or proprietary images unless the service and its privacy policy are trusted, and scope tool permissions rather than allowing Bash(infsh *).

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 25, 2026, 05:38 PM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Fcharacter-design-sheet%2F@35df87ab53af6bab4275ff4aab29895078fd364b