talking-head-production

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill's described functionality (orchestrating AI-avatar lipsync video production) is coherent with the included workflow. However, the presence of a direct curl-into-shell installer for a remote CLI (curl -fsSL https://cli.inference.sh | sh) represents a notable supply-chain risk pattern. While checksum verification is mentioned, the combination of remote installer, dynamic app IDs, and multi-step remote tooling creates nontrivial risk surfaces for tampering, version-bleed, or compromised binaries. In a real-world setting, this should be treated as SUSPICIOUS (with elevated security controls) rather than fully benign, and should be hardened by pinning installer sources, verifying signatures more robustly, and reducing reliance on such remote install flows.

Confidence: 98%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 12:32 PM
Package URL
pkg:socket/skills-sh/tul-sh%2Fskills%2Ftalking-head-production%2F@2e642cc84f58bbf26329847e4aab2c236d66dc46