ai-social-media-content

Warn

Audited by Socket on Jul 27, 2026

1 alert found:

Security
SecurityMEDIUM
skill-report.json

The fragment is primarily documentation, not a self-contained malicious program; however, it contains a critical supply-chain execution instruction: downloading a remote installer script and executing it directly via `curl -fsSL ... | sh`. This creates the potential for arbitrary code execution if the endpoint or response is compromised. Additional medium risks include instructing users to run external infsh workflows (network egress/data disclosure to providers) and optionally run automation with external side effects, plus an npx-based example that increases exposure to dynamic third-party code installation. No direct indicators of stealthy malware/persistence are evident from the provided content.

Confidence: 78%Severity: 90%
Audit Metadata
Analyzed At
Jul 27, 2026, 02:22 AM
Package URL
pkg:socket/skills-sh/aiskillstore%2Fmarketplace%2Fai-social-media-content%2F@22eaa0247b045fc8d703cd000a09c2d13fa0c57bf3923a7da161d32dad8982fa
Security Audit — socket — ai-social-media-content