social-media-carousel

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill fragment is largely coherent with its stated purpose (demonstrating and driving an AI-assisted carousel design workflow using an external CLI). However, the presence of a curl | sh download/install pattern from an external domain represents a real supply-chain risk and should be treated as suspicious by default. If this pattern is necessary for operation, it should be replaced with a pinned, auditable installation method (e.g., using a package manager with verified integrity, or vendored/bundled binaries with explicit hash checks). Overall, the content is functionally aligned but the install mechanism introduces notable risk and warrants caution and explicit trust assessment.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 25, 2026, 05:38 PM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Fsocial-media-carousel%2F@a70fd474d3e5ae9e7ecdaa30b7826ab6c7ac401d