skills-download

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the skill footprint aligns with its stated purpose of downloading and extracting skills from a remote space using credentials. It relies on environment variables for authentication and persists credentials to a workspace file when handling errors, which introduces a moderate credential-exposure risk if the workspace is not secured. There is no evident malicious behavior, but the credential handling and local persistence warrant careful access controls and secure secret management. The use of a potentially unverifiable Python package (veadk) could introduce supply-chain risk unless provenance is verified. Overall risk is moderate (securityRisk ~0.55) with potential for credential leakage if the workspace is shared or improperly secured.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 04:12 AM
Package URL
pkg:socket/skills-sh/bytedance%2Fagentkit-samples%2Fskills-download%2F@5b7a8eed018daea24337d74859814c468aef9528