infsh-cli
Warn
Audited by Socket on Sep 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the main capabilities mostly match the stated AI-runtime purpose, but the footprint is broader than necessary. Risk is driven by curl|sh installation, automatic remote upload of local files, repeated transitive skill installation, and built-in support for autonomous X/Twitter actions. This looks more like a broad remote AI automation platform than a narrowly scoped inference helper.
Confidence: 89%Severity: 76%
Audit Metadata