character-design-sheet

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s image-generation purpose matches its capabilities, and data flow appears directed to the expected inference.sh ecosystem. However, it relies on transitive skill installation and an external CLI installed via same-org but higher-risk mechanisms (npx skill add, curl|sh, mutable latest), with login credentials handled by that CLI. This is not clearly malicious, but the install and trust model is broader than a simple documentation skill.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:28 PM
Package URL
pkg:socket/skills-sh/inference-sh%2Fagent-skills%2Fcharacter-design-sheet%2F@054bff143463a5547151f7a2709ea4fbaf0b2476