llm-models

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill coherently provides a unified interface to a wide range of LLMs via a CLI-based OpenRouter integration. Its footprint—installing a standard CLI tool via npm, authenticating with a login flow, and routing prompts to model endpoints—aligns with the stated purpose. While there are minor concerns around data governance (retention/logging policies not stated) and potential cross-model data exposure due to auto-fallbacks, nothing in the described artifact indicates intentional credential harvesting or malicious activity. Overall, the risk is moderate and proportional to its purpose as a developer tool for LLM access; no immediate malicious indicators are evident based on the provided materials.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 09:33 PM
Package URL
pkg:socket/skills-sh/inference-shell%2Fskills%2Fllm-models%2F@c23ed0473200bf339e2be9c3d00679b306ec7c70