character-design-sheet

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The manifest serves a clear, workflow-aligned purpose to generate and stitch character reference assets using an external CLI and LoRA workflows. However, the installation path uses a curl -fsSL https://cli.inference.sh | sh pattern, which is a known supply-chain risk even with checksum verification. The primary risk stems from downloading and executing remote code at install time; runtime Prompts flow to an external CLI is typical but depends on trusted endpoints. Recommend replacing with a vendored or signed installer, pinning versions, or using a trusted registry, and ensuring explicit user consent for installation steps. Overall risk is elevated due to the initial download-execute pattern and external binary dependencies.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 12:31 PM
Package URL
pkg:socket/skills-sh/tul-sh%2Fskills%2Fcharacter-design-sheet%2F@35df87ab53af6bab4275ff4aab29895078fd364b