case-study-writing

Fail

Audited by Socket on Feb 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Pipe-to-shell or eval pattern detected The skill is coherent with its stated purpose (case-study writing) and contains no obvious malicious code in the skill text itself. Primary risks come from operational practices: installation via curl | sh and sending potentially sensitive customer data or executable code to inference.sh-hosted apps (research and python-executor). If inference.sh and its apps are trusted and have appropriate privacy/security controls, the skill is benign for its purpose. If not, using this skill could expose customer data or allow execution of malicious installer code. Recommendation: treat the installer step and any PII/prompts as sensitive — inspect the installer, review infsh service policies, and avoid sending confidential data without contractual/privacy safeguards. LLM verification: This SKILL.md is a legitimate documentation artifact for a case-study writing workflow that integrates a third-party CLI (infsh) and remote apps for research and visualization. The file itself contains no obfuscated or clearly malicious code, no hard-coded credentials, and no direct exfiltration routines. The primary security concerns are operational: the file recommends executing a remote shell installer via curl | sh and references remote services that would receive user prompts and potentiall

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 18, 2026, 01:41 AM
Package URL
pkg:socket/skills-sh/inferencesh%2Fskills%2Fcase-study-writing%2F@0713a9fc07b5d575dfbd613caff69a3f1ea5e1ea