fork

Fail

Audited by Socket on Feb 26, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The component's stated behavior (creating handoff documents and forking sessions into worktrees, optionally spawning teammates/background agents) is consistent with the code/text. I found no explicit hardcoded attacker-controlled network destinations, reverse shells, or deliberately obfuscated/malicious code in the provided file. However, the design enables moderate-to-high operational risk: autonomous agents, writing potentially sensitive context to disk and logs, executing external CLIs, and lack of explicit endpoint/auth controls for task orchestration. These create realistic avenues for credential leakage and supply-chain abuse if the implementation is naive or external tools are compromised. Recommended mitigations: sanitize inputs passed to shells, avoid writing secrets to handoffs, enforce strict file permissions and short lifetimes for handoff/log files, and require explicit user authorization for autonomous agent spawning.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 26, 2026, 02:21 AM
Package URL
pkg:socket/skills-sh/fairchild%2Fdotclaude%2Ffork%2F@192d102a0d2f96b5d9dc975c4f7fcecbedb59be6