agent-tools

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill is broadly scoped to orchestrate a wide array of AI apps via an external CLI and numerous third-party runtimes. While this matches the claimed purpose of “running 150+ AI apps,” the footprint includes notable supply-chain and credential/data flow risks: download-and-execute installer from a non-registry source, potential handling of credentials for multiple services, and data flowing to various external runtimes. The combination is coherent with a very powerful orchestration tool but warrants elevated caution and tight controls (verified sources, explicit data-handling policies, minimized credential exposure, and explicit permission prompts for data-sharing actions). Overall, the behavior is suspiciously broad and high-risk for an agent skill, and should be treated as high-risk/suspicious until provenance and data handling are assured.

Confidence: 60%Severity: 65%
Audit Metadata
Analyzed At
Mar 12, 2026, 09:15 AM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Fagent-tools%2F@07fff5cd7b40cd49a49c5d86527de42fae02b476