product-photography

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This repository/text is a benign prompt-and-workflow guide for generating product photography via infsh and third-party model backends. However, it instructs high-risk operational patterns: executing a remote installer via curl | sh, installing transitive npm skills, and uploading local images and credentials to remote services without detailed guidance on secure handling. These behaviors raise a moderate security risk (possible inadvertent data leakage or supply-chain compromise) rather than clear malicious code. Recommendations: avoid piping remote scripts into a shell; require pinned releases and signature verification for installers/binaries; document credential storage, token scopes, and retention; warn users to strip EXIF and review images before upload; treat npx-installed skills as untrusted until audited; restrict agent autonomy when running infsh or performing uploads.

Confidence: 98%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 12:31 PM
Package URL
pkg:socket/skills-sh/tul-sh%2Fskills%2Fproduct-photography%2F@9f51c95011c3885f48ce53e5064e73a3126cbd11