sher

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's stated purpose (build and upload a frontend for a preview URL) matches its runtime instructions, but there are inconsistencies (package/binary name mismatch) and missing auth details that merit caution before installing or running it on real code.

Before installing or running this skill: 1) Verify the CLI/package identity: confirm whether the npm package is 'shersh' or 'sher' and inspect the npm package page and its homepage (https://sher.sh) to ensure they match and are trustworthy. 2) Prefer one-off npx runs over global installs when testing. 3) Understand that running the command will upload your project files to a third-party service (sher.sh) — do not deploy repositories containing secrets, credentials, or sensitive data. 4) Ask how authentication works if you need higher quotas (what token or login flow is used and where it is stored); the skill does not declare required env vars for auth. 5) If you want extra safety, test with a small dummy repo first and/or inspect the package source code before running npm i -g. 6) If anything about the package name or homepage looks off, stop and confirm with the skill author or use an alternative hosting tool.

Static analysis

Static analysis findings are pending for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.