data-visualization
Audited by Socket on Mar 4, 2026
1 alert found:
MalwareThis skill/documentation is primarily an instructional data-visualization guide that uses a third-party CLI (infsh) to run examples remotely. The content itself is not directly malicious (no obfuscated code, no backdoors or hardcoded credentials), but it contains multiple supply-chain and data-exposure risks: a curl|sh installer pattern, examples that upload executable code and data to inference.sh, and instructions to install transitive skills via npx. These patterns make the skill SUSPICIOUS from a supply-chain and data-exfiltration perspective. Users should avoid piping installers to shell without independent verification, avoid sending sensitive data to the remote service without clear privacy guarantees, and be cautious about installing transitive skills that inherit execution privileges.