landing-page-design

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is a landing-page design guide that integrates with the inference.sh CLI to generate images and run research apps. It does not contain obvious malicious code or obfuscation in the provided text. However, it instructs users to install and run a third-party CLI via a curl|sh pipeline and to perform an infsh login, which means credentials and user-supplied prompt data will be sent to remote services. Those patterns are legitimate for a remote inference service but are high-risk supply-chain and data-exfiltration vectors if the distribution servers, CLI, or model endpoints are compromised. Recommend avoiding the direct pipe-to-shell install in automated contexts, verifying checksums from the mentioned checksums.txt before running installers, and not sending secrets or proprietary data in prompts. Overall: no confirmed malware, but moderate supply-chain and credential exposure risks.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 25, 2026, 05:38 PM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Flanding-page-design%2F@5fc2a33877e2636333787ca8929ba9e069be245f