ai-music-generation

Warn

Audited by Socket on May 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core function matches AI music generation, but trust is weakened by a mutable raw-GitHub install reference, CLI naming inconsistency (`belt` vs current documented `infsh`), broad Bash permission, and explicit transitive skill-install instructions. Data flows are broadly proportionate to the stated purpose, so this is not confirmed malware, but it carries meaningful supply-chain and trust-chain risk.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
May 13, 2026, 06:55 AM
Package URL
pkg:socket/skills-sh/inference-sh%2Fskills%2Fai-music-generation%2F@d7dd108963e242faed73dd0c8d6203a29b755ec2