Remote Experiment Execution

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches remote experimentation, but the skill grants an AI agent autonomous remote execution and iteration through an unverifiable local helper script with hidden server configuration. The main concern is not overt credential theft in the text, but high execution trust risk, opaque data flows, and autonomous action on remote infrastructure.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Apr 19, 2026, 01:28 PM
Package URL
pkg:socket/skills-sh/LigphiDonk%2FOh-my--paper%2Fremote-experiment-execution%2F@19097b35e1d9c670b5b6ee7998cc3013193abbbf