llm-models

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The analyzed workflow fulfills its stated purpose of providing multi-model access via a single CLI, but it harbors non-trivial supply-chain risks due to the download-and-execute installer pattern. Although checksum verification is claimed, the security posture hinges on robust handling of installer sources, pinned checksums, and secure credential storage during login. Recommend migrating to a trusted, signed package repository or containerized installation, explicit credential management practices, and verifiable, pinned artifact sources to reduce risk. Overall, the approach is functionally coherent but security-conscious posture must be strengthened before production use.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 25, 2026, 05:38 PM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Fllm-models%2F@ff7f8eb7ffcf5b992baf124080d2a2c838833d38