email-design

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill centers on designing emails using an external inference.sh CLI, including download-and-run install steps for a remote binary and usage of online image-generation features. While the described capabilities align with creating AI-generated visuals and layout guidance for email design, the footprint includes risky patterns: a remote install-and-execute flow (curl | sh), unverifiable binary dependency outside official registries, and potential data/credential exposure through the external CLI. These supply-chain and data-flow patterns elevate risk beyond a benign tooling helper. In its current form, the skill is Suspicious to HIGHLY SUSPICIOUS due to download-execute patterns, unverifiable binaries, and potential data exfiltration paths; it should only be used with explicit consent, hardened supply-chain controls (verified signatures, reproducible builds), and clear data-flow/privacy disclosures. If those mitigations are not possible, treat as suspicious and proceed with caution.

Confidence: 98%Severity: 72%
Audit Metadata
Analyzed At
Mar 9, 2026, 02:52 PM
Package URL
pkg:socket/skills-sh/inferencesh%2Fskills%2Femail-design%2F@421c1d736c1c53215d918d1a78fcaf59389903db