image-upscaling

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s main behavior matches its stated image-upscaling purpose, but it relies on a broad external CLI with login-based credential forwarding, a pipe-to-shell install path, and transitive skill-install commands. This looks more like a legitimate but higher-trust hosted-service wrapper than outright malware; risk is driven by supply-chain and trust expansion, not clear malicious intent.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Apr 9, 2026, 08:03 AM
Package URL
pkg:socket/skills-sh/tool-belt%2Fskills%2Fimage-upscaling%2F@ce4572d9439fb993721f276ba3ac1bf5b20470cd