status

Fail

Audited by Socket on Feb 17, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Installation of third-party script detected All findings: [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [HIGH] supply_chain: Download or install from free hosting/deployment platform detected (SC007) [AITech 9.1.4] BENIGN. The skill describes a legitimate status-check capability for Railway deployments with standard prerequisites and no suspicious data flows or credential demands. It aligns with its stated purpose and maintains proportional access (read-only status data) without hidden or external data exfiltration paths. LLM verification: Benign. The fragment is a coherent, documentation-oriented skill outline for retrieving and presenting Railway project status using standard CLI commands. While static analysis notes flag installation lines and external URLs, these pertain to documentation scaffolding rather than executable payloads or hidden data flows. No malicious data flow or credential harvesting is evident in the provided content.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 17, 2026, 04:43 AM
Package URL
pkg:socket/skills-sh/artivilla%2Fagents-config%2Fstatus%2F@affb0e27cbf427798a97aac697526a2eed834828