seo-content-brief

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill is primarily documentation and templates for creating SEO briefs but prescribes installing and using a third-party CLI (inference.sh) via an unpinned curl|sh installer and recommends installing additional skills via npx. These patterns create supply-chain and transitive-trust risks: arbitrary remote code execution at install time, reliance on project-controlled distribution domains, routing of user queries and scraped content through third-party services, and transitive installation of additional skills. I did not find explicit malicious code, obfuscation, or credential harvesting in the provided text, but the download-execute instruction and transitive installs are high-risk practices. Recommend: avoid running curl|sh without manual verification, prefer installing from trusted registries or pinned artifacts, require manual checksum verification, and review any transitive skill packages before installation.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 12:33 PM
Package URL
pkg:socket/skills-sh/tul-sh%2Fskills%2Fseo-content-brief%2F@99fd2ba4aea616ed4bce81d5cbf959dc3b5dc2d0