sandbox

Warn

Audited by Socket on Feb 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill's core purpose (live HTML canvas) is plausible and can be benign when strictly sandboxed, authenticated, and network-isolated. However the documented ability to enable JavaScript evaluation and an "unsafe sandbox," combined with no stated authentication, CSP, or network restrictions, makes this skill potentially dangerous. It enables clear exfiltration and remote code-execution-in-renderer patterns when unsafe modes are enabled. Treat as SUSPICIOUS: safe if defaults remain secure and strong mitigations are added; risky or unacceptable if operators enable unsafe flags or expose the server publicly without strict controls.

Confidence: 85%Severity: 75%
Audit Metadata
Analyzed At
Feb 20, 2026, 08:53 PM
Package URL
pkg:socket/skills-sh/alsk1992%2Fcloddsbot%2Fsandbox%2F@4b5596174854578af22af05fdf921eb8ed7f7e88