social-media-carousel

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose is mostly coherent—carousel generation through inference.sh-hosted image apps—but the skill is broader than necessary. Same-org official installer evidence lowers the chance of outright malware, yet the mutable curl|sh install path, credential use through an external CLI, wildcard `belt *` access, and explicit transitive skill installation make the overall security posture medium risk rather than benign.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 27, 2026, 02:47 AM
Package URL
pkg:socket/skills-sh/infsh-skills%2Fskills%2Fsocial-media-carousel%2F@334dbc36637ae6828d214bd2a7df5678f2dd1508