media-organizer

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The media-organizer skill aligns with its stated purpose and does not exhibit network communication, credential harvesting, or obvious malicious behavior. The primary security concern is operational: the use of powerful filesystem commands (mv and especially rm -rf) combined with acceptance of arbitrary user paths could lead to accidental or malicious data loss if confirmations are bypassed or if path handling is unsafe. Mitigations (dry-run, path validation, per-batch approvals, avoidance of shell interpolation, backup/quarantine instead of immediate deletion) reduce risk. No evidence of malware or exfiltration in the provided artifact, but the destructive-file-operation surface warrants a moderate security risk rating and careful runtime safeguards.

Confidence: 98%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 11:30 AM
Package URL
pkg:socket/skills-sh/cafe3310%2Fpublic-agent-skills%2Fmedia-organizer%2F@f9559b1cfd78fa8c31b99258f7fae3281897f45f