release

Fail

Audited by Socket on Feb 17, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Instruction directing agent to run/execute external content All findings: [CRITICAL] command_injection: Instruction directing agent to run/execute external content (CI011) [AITech 9.1.4] [HIGH] command_injection: PowerShell execution detected (CI005) [AITech 9.1.4] This skill is coherent and consistent with its stated purpose (releasing to PyPI and GitHub). There are no signs of malicious behavior in the provided instructions: required credentials and operations are proportionate and expected. Primary concerns are operational hazards (git reset --hard) and the normal sensitivity of storing PYPI_TOKEN in .env. Because the actual build_and_deploy.ps1 and the 'uv' tool are not included here, residual supply-chain risk remains if those artifacts are malicious, but nothing in this instruction file itself is malicious. LLM verification: The SKILL.md itself is a legitimate release playbook describing standard actions to bump version, build, publish to PyPI, and create a GitHub release. However it directs execution of an external PowerShell script with '-ExecutionPolicy Bypass' and relies on an unverified 'uv' CLI — both are material software supply-chain risk points. Before running these steps in any trusted environment, inspect and audit build_and_deploy.ps1 and the 'uv' tool: review their source, confirm network endpoints, res

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 17, 2026, 12:25 AM
Package URL
pkg:socket/skills-sh/brainblend-ai%2Fatomic-agents%2Frelease%2F@222b27118e7c0b520aa228f655a42f67df886feb