code-execution

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The component provides legitimate and useful capabilities for local bulk code analysis and refactoring. I found no explicit signs of embedded malware in the supplied text, but there are multiple supply-chain and privilege risks: an uninspected setup script, powerful filesystem write and git push capabilities that can lead to exfiltration, and misleading documentation claiming 'metadata only' while examples show direct source reads. Recommend auditing the setup.sh and any installed runtime components, enforcing least-privilege usage (deny git_push by default, require explicit path scopes), and adding runtime safeguards (consent prompts, dry-run, and preventing outputs that include raw source). With those controls the tool can be used safely; without them it represents a moderate supply-chain/security risk.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:03 PM
Package URL
pkg:socket/skills-sh/mhattingpete%2Fclaude-skills-marketplace%2Fcode-execution%2F@ae489a04a60b73d908ff191790af4888c1a56da7