anonymous-file-upload

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill is coherent for anonymous file hosting, but it instructs the agent to upload arbitrary local files to public third-party services and supports public posting via IPFS and temporary hosts. No clear credential theft or hidden behavior is present; the main concerns are explicit file exfiltration risk, autonomous external posting, remote URL mirroring, and unpinned container installation.

Confidence: 88%Severity: 64%
Audit Metadata
Analyzed At
Mar 18, 2026, 05:55 PM
Package URL
pkg:socket/skills-sh/besoeasy%2Fopen-skills%2Fanonymous-file-upload%2F@69fe0ed9a4ba5982fe10bf82513201fb8e16dc4a