happyhorse

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Mostly coherent media-generation skill, but it requires trusting the inference.sh `belt` CLI, references a raw GitHub install document, and encourages transitive installation of additional skills. No strong evidence of malware or credential theft is present, but the external CLI trust chain makes this medium security risk rather than fully benign.

Confidence: 80%Severity: 52%
Audit Metadata
Analyzed At
Apr 30, 2026, 01:51 PM
Package URL
pkg:socket/skills-sh/infsh-skills%2Fskills%2Fhappyhorse%2F@3272e9cc753a8b5b854f167a2ccee6a622b6762f