infsh-cli

Warn

Audited by Socket on Jun 19, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent with its stated purpose and uses same-org infrastructure, so it is not clearly malicious. However, it combines a curl|sh installer, transitive skill installation, broad bash-enabled CLI use, automatic local file uploads, and autonomous X/Twitter posting, making the overall footprint higher risk than a normal single-purpose model wrapper.

Confidence: 86%Severity: 68%
AnomalyLOW
references/authentication.md

No direct malware is evidenced in the provided fragment because it contains only installation/authentication instructions. The primary concern is supply-chain risk from executing a network-fetched installer via `curl ... | sh` without demonstrated integrity verification or pinning. Credential-handling behavior is not shown; therefore storage and secret-leakage risks cannot be confirmed or ruled out from this snippet alone. Review and verify the actual distributed CLI/installer code and enforce integrity controls before use in sensitive environments.

Confidence: 60%Severity: 65%
Audit Metadata
Analyzed At
Jun 19, 2026, 02:15 AM
Package URL
pkg:socket/skills-sh/halt-catch-fire%2Fskills%2Finfsh-cli%2F@c80c24d7f9e8d814ba1b9725487c5184b0452ca985160cce76969305ad36fa67
Security Audit — socket — infsh-cli