building-inferencesh-apps

Warn

Audited by Socket on Jun 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core purpose is coherent with the capabilities: it is a platform-specific app-development guide centered on the Belt CLI and inference.sh. Main risks are the transitive skill installation and the `curl|sh` installer, but available evidence indicates the installer is officially documented by the same vendor ecosystem rather than an arbitrary third-party payload. No clear malicious data exfiltration or credential harvesting is present.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Jun 19, 2026, 02:15 AM
Package URL
pkg:socket/skills-sh/halt-catch-fire%2Fskills%2Fbuilding-inferencesh-apps%2F@42e671d0bca74eab7d47b4227e037fe7b6f569686ad86aee539038b13d1f90b6
Security Audit — socket — building-inferencesh-apps