data-visualization

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This package is primarily documentation and runnable examples for data visualization using a remote executor (inference.sh). The code samples are benign and non-obfuscated. The dominant security concerns are supply-chain and data-exposure risks introduced by the recommended install pattern (curl | sh), remote execution of user-supplied payloads, and broad CLI permissions (allowed-tools: Bash(infsh *)). There are no hardcoded secrets or clear indicators of intentionally malicious code in the provided file. Recommended mitigations: avoid piping unknown install scripts to a shell, perform checksum verification manually or use package manager installs when possible, do not include secrets or PII in infsh payloads, limit CLI permissions, and prefer local execution for sensitive data.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 25, 2026, 05:40 PM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Fdata-visualization%2F@8d16b1a837a07b7f66b4e74fb8718086a0974758