agentscope-skill

Fail

Audited by Socket on Feb 26, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
references/multi_agent_orchestration.md

The provided code itself is not overtly malicious, but it exposes a high-risk capability (execute_shell_command) to agent-driven workflows that accept untrusted input. Without sandboxing, input validation, authorization, and auditing, an agent (or a poisoned prompt) could cause arbitrary command execution, data leakage, or system modification. Treat examples exposing shell execution as dangerous primitives; enforce strict controls before deploying in production.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 26, 2026, 01:41 AM
Package URL
pkg:socket/skills-sh/agentscope-ai%2Fagentscope-skills%2Fagentscope-skill%2F@a118c35241f5a55c1a8a2885b5cf58942c720683