customer-persona
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core persona-research behavior is coherent with the stated purpose, and the referenced inference.sh tooling appears same-org and legitimate. Risk comes from the transitive skill installation step, broad wildcard `infsh` execution, and routing user data through third-party CLI/app providers rather than from clear malicious intent.
Confidence: 85%Severity: 59%
Audit Metadata