infsh-cli

Warn

Audited by Socket on May 17, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/authentication.md

No direct malware is evidenced in the provided fragment because it contains only installation/authentication instructions. The primary concern is supply-chain risk from executing a network-fetched installer via `curl ... | sh` without demonstrated integrity verification or pinning. Credential-handling behavior is not shown; therefore storage and secret-leakage risks cannot be confirmed or ruled out from this snippet alone. Review and verify the actual distributed CLI/installer code and enforce integrity controls before use in sensitive environments.

Confidence: 60%Severity: 65%
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with its stated purpose and the main installer appears to be an official same-org distribution, so it is not confirmed malware. Risk comes from the curl|sh install path, broad Bash access, automatic local file uploads, transitive skill installation, and especially the ability to perform autonomous X/Twitter actions on the user's behalf.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
May 17, 2026, 06:43 AM
Package URL
pkg:socket/skills-sh/inference-sh-skills%2Fskills%2Finfsh-cli%2F@a8aed7ebef1fa10c2e3a095218c13e131ea8a004
Security Audit — socket — infsh-cli