infer-upgrade

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is largely coherent with its stated purpose as an Infer updater, but it performs unpinned remote package execution and a transitive skill installation (`npx skills add`) that expands trust beyond a routine local upgrade. No obvious credential theft or exfiltration is present, so this is not malware, but it is a medium-risk maintenance skill that should only be used if the `@inferevents` packages and `infer-events/skills` source are verified as official.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
Apr 4, 2026, 04:39 AM
Package URL
pkg:socket/skills-sh/infer-events%2Fskills%2Finfer-upgrade%2F@e55e4d2a05838aca27edc0eab5365ef0294f937f