ecosystem-orchestration

Fail

Audited by Socket on Mar 5, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The file itself is not an immediate code payload, but it prescribes running a centralized installer that will install multiple transitive skills without providing provenance, pinned sources, or verification steps. This pattern creates a substantial software supply-chain risk: a compromised installer or upstream package can gain agent privileges and perform malicious actions (exfiltration, credential harvesting, destructive operations). Recommend: do not run install_all.py until its contents and all transitive manifests are audited; require explicit per-skill sources, pinned versions, checksums or signatures, interactive per-skill permission grants, and network endpoint whitelists. Treat the installer and any transitive installs as high-risk until audited.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 5, 2026, 06:29 PM
Package URL
pkg:socket/skills-sh/fatih-developer%2Ffth-skills%2Fecosystem-orchestration%2F@28ba8d64f02c47431f80a14faa56b9e0bbedbb92