youtube-thumbnail-design

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill documentation is coherent with a legitimate purpose (helping creators produce thumbnails via a hosted AI image CLI). However, it contains high-risk supply-chain instructions: specifically the curl | sh installer and reliance on multiple remote components and unpinned package installs. The documentation omits important details about where credentials go and how user data is stored/retained. Practically: the content is not itself malicious, but following the provided install/run commands carries a non-trivial supply-chain and credential risk. Users should avoid piping remote scripts to sh, verify checksums independently, inspect installer contents before execution, and review the CLI's privacy/auth documentation before sending sensitive prompts or credentials.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 25, 2026, 05:38 PM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Fyoutube-thumbnail-design%2F@f7f80620bf75fab1d3aee563439c9567601e454d