data-visualization

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill alignment appears to be semantically coherent with a data-visualization workflow using an external CLI. However, the footprint includes a download-and-execute supply-chain pattern from an unverifiable binary, which significantly elevates security risk. The combination of an unverified remote binary plus a curl|bash-like installation flow makes the risk profile suspicious to high, despite the intended visualization functionality. Recommend requiring verifiable, signed binaries from official registries or distributing the tool as a container image with strict provenance, plus detailed per-command permission scoping and sandboxing of the execution environment.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/1nfsh-s3%2Fskills%2Fdata-visualization%2F@a0d23e61b7818cbe1837cb38c70920eeeaf28d46
Security Audit — socket — data-visualization