ai-content-pipeline

Fail

Audited by Socket on Feb 21, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Pipe-to-shell or eval pattern detected This skill documentation is functionally coherent with its stated purpose (multi-step content pipelines) but presents significant supply-chain and data-exposure risks. The pipe-to-shell installer (curl | sh) and unpinned remote installer are the highest-risk elements. The workflow also forwards user prompts, media, and likely credentials to many third-party services without clear data governance. Recommend treating this as suspicious: do not run the installer without verifying its provenance and checksum; prefer installing via official package managers or pinned releases; audit which backends receive data and require minimal scopes/explicit consent. LLM verification: The documentation describes legitimate, useful workflows for building AI-driven media pipelines. The primary security concern is the installer pattern `curl -fsSL https://cli.inference.sh | sh` and the centralization of data/credentials via the infsh CLI/backend. These create supply-chain and data-exposure risks (arbitrary code execution at install, potential credential capture, and mass exfiltration of uploaded content). There is no direct indication of embedded malware or obfuscation in the RE

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 21, 2026, 04:58 PM
Package URL
pkg:socket/skills-sh/NeverSight%2Fskills_feed%2Fai-content-pipeline%2F@822cd0e0f93b0c75f3f7edfec409a0dbe0abe3b5