modal-sandbox

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Benign overall, with normal risk for a tool that runs untrusted code in isolated sandboxes and exposes services via tunnels. The footprint is coherent with the stated purpose, but the combination of long-lived controller processes, public service exposure, and runtime file/uploads increases risk if access controls are misconfigured or secrets are mishandled. Recommend explicit secret management guidance, safe defaults for network exposure (tighten cidr_allowlist, require create_connect_token with scoped access), and clear prompts to user about sandbox lifecycle actions that have real-world effects.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 05:52 PM
Package URL
pkg:socket/skills-sh/jamesrobmccall%2Fmodal_skills%2Fmodal-sandbox%2F@d872deef45ef55dbf21f2ae3ea5a6039047cb4a7