skill-auditor

Warn

Audited by Socket on Mar 6, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/apply_patches.py

I found no explicit embedded malware (no networking, no eval/exec, no obfuscation artifacts). The code is functionally a local file-modification utility that will overwrite arbitrary files specified in .patch.json inputs when run with --confirm. That makes it dangerous if patch files are untrusted — an attacker with ability to drop or modify patches can modify or corrupt any file the process user can write. Treat this as an operational supply-chain risk: safe to use only with authenticated, validated patch inputs and path allowlisting.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Mar 6, 2026, 05:12 AM
Package URL
pkg:socket/skills-sh/nyosegawa%2Fskills%2Fskill-auditor%2F@5e08bc12e3255057048343823400d2aebaa1a6c6