infsh-cli

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
references/authentication.md

No direct malware is evidenced in the provided fragment because it contains only installation/authentication instructions. The primary concern is supply-chain risk from executing a network-fetched installer via `curl ... | sh` without demonstrated integrity verification or pinning. Credential-handling behavior is not shown; therefore storage and secret-leakage risks cannot be confirmed or ruled out from this snippet alone. Review and verify the actual distributed CLI/installer code and enforce integrity controls before use in sensitive environments.

Confidence: 60%Severity: 65%
Audit Metadata
Analyzed At
Apr 22, 2026, 04:25 PM
Package URL
pkg:socket/skills-sh/inference-shell%2Fskills%2Finfsh-cli%2F@b8ef3e4853ae898a2fec9e58e55f0bbe67994792
Security Audit — socket — infsh-cli