pitch-deck-visuals

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill aligns with its stated purpose of producing investor-focused pitch deck visuals via the infsh CLI. The footprint remains reasonably scoped to containerized CLI usage and templated visuals. However, there are potential risks around transitive skill installation, credential handling via the CLI, and possible data flows to external rendering services. The overall risk is low-to-moderate (securityRisk ~ 0.28) with no clear indicators of malicious intent, but the patterns merit caution, especially around automatic installation of external tools and any credential handling in real deployments.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 09:29 PM
Package URL
pkg:socket/skills-sh/inference-shell%2Fskills%2Fpitch-deck-visuals%2F@3e0e71d9110081cbe637abfaaff342130723ee77