env-debug

Fail

Audited by Socket on Feb 21, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Destructive bash command detected (rm -rf, chmod 777) Benign: The skill/content is coherent with its stated purpose of environment debugging and troubleshooting. It uses standard, well-known shell commands and provides non-destructive guidance. There are placeholder credentials only as examples; no secret collection, exfiltration, or automated external actions are evident. LLM verification: This is a developer-facing environment-debugging instruction file. It is largely benign and aligned with its stated purpose. The primary risks are accidental: destructive commands (rm -rf, docker system prune), package installs (npm install/npx) which increase supply-chain exposure, and guidance that can reveal secrets to terminal history or logs (echo $API_KEY, printing env). No evidence of intentional data exfiltration, backdoors, obfuscation, or network endpoints that harvest credentials was

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 21, 2026, 07:03 AM
Package URL
pkg:socket/skills-sh/1mangesh1%2Fdev-skills-collection%2Fenv-debug%2F@80f70267a76569b5f28f41e6b2387fea6cadc61d