higgsfield-product-photoshoot

Warn

Audited by Socket on Aug 18, 2026

1 alert found:

Security
SecurityMEDIUM
skill-report.json

Security risk is elevated primarily due to a documented pipe-to-shell installation command using a hardcoded remote installer URL, which is a supply-chain/RCE threat if the remote script changes or is compromised. Separately, the workflow described can upload local product images (and prompt intent) to an external backend, creating privacy and data-handling exposure risk if users provide sensitive assets without clear consent. No direct evidence of embedded malware/persistence is shown in the provided fragment.

Confidence: 62%Severity: 78%
Audit Metadata
Analyzed At
Aug 18, 2026, 12:04 PM
Package URL
pkg:socket/skills-sh/aiskillstore%2Fmarketplace%2Fhiggsfield-product-photoshoot%2F@2175684dee080e4245a6c6ededc2e1db822844c9cc55192644671a10503d96fd
Security Audit — socket — higgsfield-product-photoshoot