aif

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose mostly matches project setup, but the actual footprint includes high-risk transitive skill installation from an external ecosystem, unpinned `npx` execution, and a CLI/documentation mismatch that weakens install trust. The built-in scanner is a mitigating control, not a full defense, so overall this is a high security-risk setup skill rather than confirmed malware.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
May 8, 2026, 01:50 PM
Package URL
pkg:socket/skills-sh/lee-to%2Fai-factory%2Faif%2F@557adabb3e698122f5f582c6b5957ccdca3f6217