customer-persona

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core persona-research behavior is coherent with the stated purpose, and the referenced inference.sh tooling appears same-org and legitimate. Risk comes from the transitive skill installation step, broad wildcard `infsh` execution, and routing user data through third-party CLI/app providers rather than from clear malicious intent.

Confidence: 85%Severity: 59%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:30 PM
Package URL
pkg:socket/skills-sh/inference-sh%2Fagent-skills%2Fcustomer-persona%2F@8b0f72ddafa15a456e6e17c8a07dddf4d4073d45