pitch-deck-visuals

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is functionally plausible for generating pitch-deck visuals, but it contains multiple supply-chain and data-exposure risks. The most significant issues are the curl|sh quick-start installer and the reliance on remote inference/executor services that accept arbitrary HTML, code, and image prompts. Transitive installation of third-party skills and the broad allowed-tools (infsh *) increase attack surface: malicious or compromised upstream components could execute code, harvest credentials, or exfiltrate slide content. Recommended mitigations: avoid pipe-to-shell installs (provide pinned releases and manual verification steps), clearly document credential handling and retention for infsh login, warn users about sending proprietary data to remote services, and minimize allowed-tools or require explicit user consent before transitive installs or remote code execution.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 12:32 PM
Package URL
pkg:socket/skills-sh/tul-sh%2Fskills%2Fpitch-deck-visuals%2F@4bfa4bff3afd975c1b17634ba1face97f832888b