data-visualization
Fail
Audited by Socket on Mar 8, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
The skill alignment appears to be semantically coherent with a data-visualization workflow using an external CLI. However, the footprint includes a download-and-execute supply-chain pattern from an unverifiable binary, which significantly elevates security risk. The combination of an unverified remote binary plus a curl|bash-like installation flow makes the risk profile suspicious to high, despite the intended visualization functionality. Recommend requiring verifiable, signed binaries from official registries or distributing the tool as a container image with strict provenance, plus detailed per-command permission scoping and sandboxing of the execution environment.
Confidence: 75%Severity: 75%
Audit Metadata