ai-content-pipeline
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose matches media-pipeline behavior, and the `infsh` installer appears to be an official same-org dependency, so this is not strong evidence of malware. Risk comes from broad Bash permissions, reliance on an external CLI, instructions to install additional skills, and workflows that may process untrusted content and automate downstream publishing.
Confidence: 84%Severity: 58%
Audit Metadata