ai-music-generation

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core function matches AI music generation, but trust is weakened by a mutable raw-GitHub install reference, CLI naming inconsistency (`belt` vs current documented `infsh`), broad Bash permission, and explicit transitive skill-install instructions. Data flows are broadly proportionate to the stated purpose, so this is not confirmed malware, but it carries meaningful supply-chain and trust-chain risk.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
May 5, 2026, 12:30 PM
Package URL
pkg:socket/skills-sh/infsh-skills%2Fskills%2Fai-music-generation%2F@c7c62a37b0f39b77186f2e8120f332138bec77f3
Security Audit — socket — ai-music-generation