python-env

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill concept is coherent for a Python environment management workflow using uv; however, it hinges on downloading and executing an external install script from an unverifiable domain, which introduces non-trivial supply-chain risk. This pattern elevates securityRisk and warrants caution: the tool could deliver any payload or modify the host beyond the intended Python environment management. If the installer source is replaced with a verifiable, signed binary from an official registry or a well-known, auditable package (e.g., a published npm/pip/cargo package or a checksum-verified installer), the risk would be substantially reduced and the footprint would align better with the stated purpose.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 8, 2026, 04:19 PM
Package URL
pkg:socket/skills-sh/0xdarkmatter%2Fclaude-mods%2Fpython-env%2F@d8f142118704be2b292bed873a76d16d2eaef4ab