data-visualization
Fail
Audited by Snyk on Feb 15, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.90). Suspicious — the sites (inference.sh and cli.inference.sh) are an unvetted .sh domain with a dedicated installer endpoint and the skill instructs users to run "curl ... | sh", which executes remote code fetched from an unknown source and is a common vector for malware distribution.
Audit Metadata