prompt-engineering

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is a prompt-engineering guide that references and instructs installing and using the inference.sh CLI. The content itself is not overtly malicious (no hardcoded secrets, no obfuscated payloads, no reverse shells visible). However, it includes high-risk supply-chain patterns: a curl|sh installer (download-and-execute), remote binary downloads, and recommendations to install transitive skills. Those patterns expand trust to remote domains (cli.inference.sh / dist.inference.sh) and to any third-party skills installed later. The primary risks are supply-chain compromise or credential/exfiltration via the installed CLI or transitive skills. Treat this as suspicious: if you must use it, avoid pipe-to-shell installs, verify checksums manually, inspect install scripts and binaries, prefer platform package managers or vetted installers, and audit any transitive skills before installing.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 12:33 PM
Package URL
pkg:socket/skills-sh/tul-sh%2Fskills%2Fprompt-engineering%2F@294526bd6c7c18de489358ce2ed817c60a2a3fb3