code-mode

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Code Mode skill concept is coherent with its purpose of reducing context size by executing user-provided scripts in a sandbox and returning only processed output. While the high-level outline is plausible for a legitimate developer tool, the document lacks explicit, enforceable sandbox guarantees (filesystem/network isolation, resource limits, verifiable dependency management, and explicit data-escape controls). Absent those specifics, the risk is moderate: functional design is sound, but security posture depends on concrete sandboxing implementation. The approach is suspicious only if sandbox boundaries prove weak in practice; otherwise, it remains a benign to moderately risky developer tool aimed at improving efficiency.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 01:06 PM
Package URL
pkg:socket/skills-sh/chenhunghan%2Fcode-mode-skill%2Fcode-mode%2F@3a2240a618d724da367a1ad55c4d1092d59e30d8