infsh-cli

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the main capabilities mostly match the stated AI-runtime purpose, but the footprint is broader than necessary. Risk is driven by curl|sh installation, automatic remote upload of local files, repeated transitive skill installation, and built-in support for autonomous X/Twitter actions. This looks more like a broad remote AI automation platform than a narrowly scoped inference helper.

Confidence: 89%Severity: 76%
Audit Metadata
Analyzed At
Sep 18, 2026, 09:30 PM
Package URL
pkg:socket/skills-sh/inference-sh%2Fskills%2Finfsh-cli%2F@ebec2a769497a86e127bd7c5f08f32c9a8db7615e9e086f8d1957ed6224b4c3e
Security Audit — socket — infsh-cli