script-test

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill fragment is internally consistent with a testing script-execution purpose but relies on auto-execution of a shell script, which is a high-risk capability. For secure use, enforce explicit user confirmation, restrict the script to a safe, sandboxed environment, and implement allowlists for scripts and environment variables. The documentation also shows signs of truncation, which warrants review before deployment. Recommend adding: explicit confirmation prompt, sandboxed execution with timeouts and resource limits, script whitelisting, environment-variable scoping, and clearer bounds on data exposure during/after execution.

Confidence: 58%Severity: 58%
Audit Metadata
Analyzed At
Feb 16, 2026, 09:33 AM
Package URL
pkg:socket/skills-sh/leavesfly%2Fjimi%2Fscript-test%2F@4e1bc720825758c76182c79787a1addf9aef887b