managing-temp-scripts

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is functionally consistent with its stated purpose (creating and running temporary scripts), but its capabilities are broad and inherently powerful. The fragment contains multiple risky practices: executing arbitrary generated code, installing packages at runtime from public registries, passing credentials on the command line, and writing .env files to /tmp without enforced secure defaults or sandboxing. Those behaviors are legitimate for some use cases but create substantial supply-chain and credential-exfiltration risk if misused or if attackers can influence script contents/dependencies. Verdict: SUSPICIOUS — usable but high-risk without additional runtime safeguards and stricter handling of secrets and dependency installation.

Confidence: 78%Severity: 62%
Audit Metadata
Analyzed At
Feb 16, 2026, 02:42 AM
Package URL
pkg:socket/skills-sh/mbruhler%2Fclaude-orchestration%2Fmanaging-temp-scripts%2F@7c54ce6f3b65c820fc02dd37d4eeaa9dda3a4e35