email-design
Audited by Socket on Mar 9, 2026
1 alert found:
MalwareThe skill centers on designing emails using an external inference.sh CLI, including download-and-run install steps for a remote binary and usage of online image-generation features. While the described capabilities align with creating AI-generated visuals and layout guidance for email design, the footprint includes risky patterns: a remote install-and-execute flow (curl | sh), unverifiable binary dependency outside official registries, and potential data/credential exposure through the external CLI. These supply-chain and data-flow patterns elevate risk beyond a benign tooling helper. In its current form, the skill is Suspicious to HIGHLY SUSPICIOUS due to download-execute patterns, unverifiable binaries, and potential data exfiltration paths; it should only be used with explicit consent, hardened supply-chain controls (verified signatures, reproducible builds), and clear data-flow/privacy disclosures. If those mitigations are not possible, treat as suspicious and proceed with caution.