eval-config

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The eval-config skill/specification is functionally coherent and requires access to multiple local brand artifacts and a local management script to do its job. The main security concerns are: (1) executing a local management script with user-supplied arguments (supply-chain / execution risk), (2) reading and presenting historical evaluation data (privacy/exposure risk), and (3) the potential for an overprivileged agent to make destructive configuration changes without strict confirmation, auditing, and least-privilege controls. Recommended mitigations: code-review and integrity checks (signatures/checksums) for scripts/eval-config-manager.py, restrict file access and redact outputs of historical evaluations, enforce explicit user confirmation and detailed logging for any config changes, run management scripts in a constrained runtime (least privilege, sandbox), and add release/supply-chain protections for any packages providing the scripts or agent components.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 27, 2026, 01:05 PM
Package URL
pkg:socket/skills-sh/indranilbanerjee%2Fdigital-marketing-pro%2Feval-config%2F@8024b2db358763694fc6000adc8db767070a5887