logo-design-guide

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The file is a benign operational guide for logo design with AI, but it prescribes high-risk supply-chain and data-exfiltration vectors: a pipe-to-shell installer, central reliance on a third-party binary/distribution, credential-based login, and dynamic package installs via npx. These patterns are common for legitimate CLIs but amplify risk if the remote distribution or packages are compromised. I do not find code-level obfuscation or embedded malware in the document, but the recommended operational steps warrant caution and procedural mitigations before executing on a host or uploading sensitive data.

Confidence: 98%Severity: 90%
Audit Metadata
Analyzed At
Feb 25, 2026, 05:38 PM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Flogo-design-guide%2F@570027d89487d9a6e10d82fd40efbe3fbbb9bf4a