product-changelog

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill/instruction document is primarily benign and focused on changelog writing and generating visuals via the inference.sh CLI. However, it contains multiple supply-chain and data-flow patterns that elevate security risk: a curl|sh install flow, downloads from dist.inference.sh, implicit credential usage via `infsh login`, sending user inputs and local screenshots to third-party apps run through the infsh service, and examples encouraging transitive installs via npx. These behaviors are proportionate to the stated functionality (remote model/app execution and CLI installs) but require caution: the download-execute pattern and transitive installs are high-risk supply-chain vectors, and the documentation lacks detail about how credentials and uploaded files are protected. Recommend avoiding piping remote scripts to shell, verifying checksums out-of-band, being cautious not to upload secrets or sensitive URLs to remote app runs, and auditing any transitive skills before installing.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 12:32 PM
Package URL
pkg:socket/skills-sh/tul-sh%2Fskills%2Fproduct-changelog%2F@b3a450f7986c1c898f601b79f0781bdc5b223896