ncine-presentation

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Destructive bash command detected (rm -rf, chmod 777) All findings: [CRITICAL] command_injection: Destructive bash command detected (rm -rf, chmod 777) (CI004) [AITech 9.1.4] [CRITICAL] command_injection: Destructive bash command detected (rm -rf, chmod 777) (CI004) [AITech 9.1.4] Benign overall. The manifest and instructions align with the stated purpose of a Slidev-based presentation template. Deployment steps use conventional tools (vercel, netlify) and rely on environment variables for credentials, which is standard but requires careful handling to avoid leakage in logs. No hardcoded secrets or malicious behavior detected. LLM verification: The fragment is a legitimate setup/deployment guide for a Slidev-based project but contains dangerous commands (rm -rf, chmod 777) documented as steps. These commands pose real risk if executed without caution. Improve safety by removing or guarding destructive steps, replacing broad permission changes with least-privilege defaults, and clearly labeling optional destructive actions with warnings and confirmations.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:35 PM
Package URL
pkg:socket/skills-sh/eng0ai%2Feng0-template-skills%2Fncine-presentation%2F@39291daaae6875cbbcd423b0d4f6796be402a84c