background-removal

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The repository appears to be legitimate documentation for a hosted image background-removal service using inference.sh and the BiRefNet model. No explicit malicious code is visible in the provided text, but there are notable supply-chain and privacy risks: the pipe-to-shell installer pattern, insufficient detail about credential handling, and encouragement to install third-party skills via npx increase attack surface. Recommend avoiding curl|sh, verifying checksums if installing, auditing any npx skill packages before use, and assessing inference.sh's data retention and token scope policies before sending sensitive images or credentials.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 12:33 PM
Package URL
pkg:socket/skills-sh/tul-sh%2Fskills%2Fbackground-removal%2F@7ee020cdf1114808c0b634b988fb28867b691e53