python-executor

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core function is coherent—a remote Python sandbox via inference.sh—and the CLI installer appears to be official same-org infrastructure, which lowers supply-chain concern. However, the skill materially expands agent capability to arbitrary remote code execution with web scraping/automation, broad belt CLI access, and transitive skill installation instructions, making overall risk medium even without clear malicious intent.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Apr 23, 2026, 07:52 AM
Package URL
pkg:socket/skills-sh/inference-sh%2Fskills%2Fpython-executor%2F@e6565973ad6d84ddc519dbea701ad715b7b23f9c