infer-setup

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with an analytics setup workflow, but it combines sensitive local credential handling, mutable npm-based execution of an MCP server, project-wide code inspection/modification, and transitive skill installation. The data flow appears directed to Infer endpoints rather than an obvious third-party exfiltration service, so this is not confirmed malware, but the trust and credential footprint are larger than a minimal SDK integration and warrant medium-to-high caution.

Confidence: 84%Severity: 66%
Audit Metadata
Analyzed At
Apr 4, 2026, 04:40 AM
Package URL
pkg:socket/skills-sh/infer-events%2Fskills%2Finfer-setup%2F@71d4b2f9f605469661d5bdb1fef446c96190b20d