happyhorse

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Mostly coherent media-generation skill, but it requires trusting the inference.sh `belt` CLI, references a raw GitHub install document, and encourages transitive installation of additional skills. No strong evidence of malware or credential theft is present, but the external CLI trust chain makes this medium security risk rather than fully benign.

Confidence: 80%Severity: 52%
Audit Metadata
Analyzed At
May 4, 2026, 08:35 PM
Package URL
pkg:socket/skills-sh/inference-sh%2Fskills%2Fhappyhorse%2F@3272e9cc753a8b5b854f167a2ccee6a622b6762f