flux-image

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill documentation describes using a third-party CLI (infsh) and hosted inference service (inference.sh) to run FLUX models. The primary security concerns are supply-chain and credential risks from the curl|sh installer pattern and trusting remote binaries (dist.inference.sh). Requiring `infsh login` means user credentials will be sent to the service; this is expected but sensitive. There is no direct evidence of malicious code, hardcoded secrets, obfuscation, or covert exfiltration in the fragment, but the download-and-execute pattern and dependency on an opaque CLI justify a moderate security risk posture. Recommend users avoid unattended curl|sh installs, verify checksums manually, review the infsh binary source or install from a package manager if available, and review infsh's credential storage and privacy policy before use.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 25, 2026, 05:38 PM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Fflux-image%2F@a58d3fb37e3b01a7ed157f9283102da23ebba2d0