image-upscaling
Audited by Socket on Feb 19, 2026
1 alert found:
Malware[Skill Scanner] Pipe-to-shell or eval pattern detected This skill is documentation for a remote image-upscaling workflow that uses the inference.sh CLI and third-party app backends. There is no direct malicious code here, but the recommended installation method (curl | sh) and the fact that user images and authentication flow to remote services create measurable supply-chain and data-exfiltration risk. Treat the remote installer and inference.sh platform as high-value trust boundaries: review the install script contents before running, confirm the platform's privacy and credential handling policies, and prefer audited/package-manager installs when available. LLM verification: The README/documentation itself is not directly malicious, but it recommends high-risk operational patterns: a pipe-to-shell installer and workflows that send user images and credentials to a hosted service and third-party app backends without disclosure of data handling practices. These patterns constitute a non-trivial supply-chain and privacy risk: compromise of the installer or platform could lead to remote code execution or data exfiltration. I classify the artifact as suspicious for supply