NYC

update

Warn

Audited by Socket on Feb 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The workflow accomplishes its stated goal but introduces moderate-to-high supply-chain risk due to use of npx@latest, global installation, and forced overwrites of user skill directories without integrity checks. There is no direct evidence in the provided fragment of explicit malicious payloads or network endpoints, but the operational pattern (unvetted remote code execution and silent file overwrite) is a common vector for supply-chain compromises. Treat this as a security alert: audit or pin the package and run installations in an isolated environment; do not execute the exact commands on sensitive systems without these mitigations.

Confidence: 75%Severity: 60%
Audit Metadata
Analyzed At
Feb 19, 2026, 08:55 PM
Package URL
pkg:socket/skills-sh/boshu2%2Fagentops%2Fupdate%2F@d19ce88270dde33df4b20e7987bc5d473fa69cd1