swarm

Warn

Audited by Socket on Mar 6, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/swarm.sh

The script itself is an orchestration tool (not obviously malware). However it intentionally disables safety controls when invoking external LLM runtimes and runs package managers and git operations that can lead to arbitrary code execution or destructive repository changes. The primary risk is operational: untrusted prompts, agent behavior, or dependencies can modify or damage the repository or execute arbitrary code. Treat this as a moderately high-risk tool to run in non-sandboxed environments.

Confidence: 85%Severity: 60%
Audit Metadata
Analyzed At
Mar 6, 2026, 06:59 AM
Package URL
pkg:socket/skills-sh/jonmumm%2Fskills%2Fswarm%2F@55f3ac2f47dcd161bd306ec56faded1c75f33cf7