technical-blog-writing

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill fragment is primarily a structured guide for technical blog writing with embedded examples that rely on an external CLI (infsh) and remote installer scripts. This creates a legitimate but non-trivial download/execute pattern and external data flows, which are a supply-chain risk vector if the source or binaries are compromised. The stated purpose (guiding technical blog content creation) is coherent with the capability to invoke external generation tools, but the install/download pattern and cross-service interactions elevate risk. Treat as SUSPICIOUS due to the download-and-execute pattern and external dependencies; classify as HIGH risk if this skill is used in production agent pipelines without strict source verification, explicit per-action user consent, and minimized external data exfiltration routes.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 12:32 PM
Package URL
pkg:socket/skills-sh/tul-sh%2Fskills%2Ftechnical-blog-writing%2F@115b89a0738e3a07f1719c4acb866a7e4c6658da