higgsfield-product-photoshoot
Warn
Audited by Socket on Aug 18, 2026
1 alert found:
SecuritySecurityskill-report.json
MEDIUMSecurityMEDIUM
skill-report.json
Security risk is elevated primarily due to a documented pipe-to-shell installation command using a hardcoded remote installer URL, which is a supply-chain/RCE threat if the remote script changes or is compromised. Separately, the workflow described can upload local product images (and prompt intent) to an external backend, creating privacy and data-handling exposure risk if users provide sensitive assets without clear consent. No direct evidence of embedded malware/persistence is shown in the provided fragment.
Confidence: 62%Severity: 78%
Audit Metadata