terminal

Warn

Audited by Socket on Apr 11, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's stated purpose matches its capability, but that capability is unrestricted shell execution through an unseen local script. There is no explicit malware or credential-harvesting path in the provided text, yet the skill gives an AI agent broad system power with minimal visible safeguards, making overall security risk high.

Confidence: 87%Severity: 82%
SecurityMEDIUM
terminal_cli.sh

This module is a high-risk command-execution wrapper: untrusted JSON input supplies an arbitrary `command` that is executed via `bash -c`, optionally with attacker-influenced timeout behavior. While there is no explicit malicious payload shown, the design provides a direct remote command execution capability and returns captured command output to the caller. Additionally, the JSON encoding of output is incomplete (notably on the failure path), increasing the risk of malformed responses or injection into downstream consumers. Overall, treat as dangerous unless stdin is strictly trusted and the execution environment is tightly controlled/sandboxed.

Confidence: 78%Severity: 90%
Audit Metadata
Analyzed At
Apr 11, 2026, 10:49 AM
Package URL
pkg:socket/skills-sh/DotNetAge%2Fmindx%2Fterminal%2F@a45280f1fd294a7edfaf0e1331e85607785f58df