script-test
Warn
Audited by Socket on Feb 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill fragment is internally consistent with a testing script-execution purpose but relies on auto-execution of a shell script, which is a high-risk capability. For secure use, enforce explicit user confirmation, restrict the script to a safe, sandboxed environment, and implement allowlists for scripts and environment variables. The documentation also shows signs of truncation, which warrants review before deployment. Recommend adding: explicit confirmation prompt, sandboxed execution with timeouts and resource limits, script whitelisting, environment-variable scoping, and clearer bounds on data exposure during/after execution.
Confidence: 58%Severity: 58%
Audit Metadata