context-engineering-collection

Fail

Audited by Socket on Apr 15, 2026

2 alerts found:

AnomalyMalware
AnomalyLOW
skills/hosted-agents/SKILL.md

SUSPICIOUS: the skill is coherent as hosted-agent infrastructure guidance, not overt malware, but it normalizes high-impact autonomous behavior, sensitive GitHub token handling, and broad remote execution. Risk is driven by scope and execution model rather than deceptive data exfiltration; the OpenCode curl|bash reference is a secondary supply-chain concern, not the main issue.

Confidence: 87%Severity: 68%
MalwareHIGH
examples/interleaved-thinking/SKILL.md

SUSPICIOUS: The stated purpose is coherent for an agent-debugging skill, and the only evidenced API flow aligns with official MiniMax endpoints. However, the undocumented and unverifiable `rto` CLI is a major install-trust gap, and the skill handles highly sensitive reasoning/session traces with optional prompt mutation and skill generation. Main concern is execution provenance and trace exposure, not confirmed malware.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Apr 15, 2026, 05:42 AM
Package URL
pkg:socket/skills-sh/muratcankoylan%2Fagent-skills-for-context-engineering%2Fcontext-engineering-collection%2F@7a95d94c364e25c869a86896a45791dfda6db8bf