sandbox-sdk

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This document is a benign SDK documentation page describing a sandboxed code execution product with expected risky capabilities (exec/runCode/exposePort). The capabilities are coherent with the purpose, but the documentation omits critical operational controls: network egress policies, secret management guidance, authentication/authorization for preview URLs, and pinned/verifiable image/package sources. These omissions increase supply-chain and operational risk. There is no direct evidence of malicious intent in the provided text, but using the SDK without strict isolation, network controls, and proper secret handling could enable data exfiltration or exposure of sensitive credentials.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 27, 2026, 04:36 AM
Package URL
pkg:socket/skills-sh/mksglu%2Fskills%2Fsandbox-sdk%2F@ebb6ace4d874ef096156bda772dd3e4c59e1eb30