safe-rm

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill’s behavior matches its stated purpose and I found no credential access, exfiltration, or hidden network routing, so it does not look malicious. However, its core value proposition is letting the agent perform destructive file deletions without asking permission, which is high-impact autonomy for a local system action, and the install path has mild supply-chain hygiene issues due to a mutable GitHub archive.

Confidence: 90%Severity: 62%
Audit Metadata
Analyzed At
Mar 18, 2026, 11:10 PM
Package URL
pkg:socket/skills-sh/aspiers%2Fai-config%2Fsafe-rm%2F@843a40399442d604aa976d9074ff220f8fb9c81c