destructive-command-guard

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the stated purpose is coherent and defensive, but the install trust is weak. A safety hook that blocks destructive commands fits the claimed purpose, yet the skill asks users to install an unpublished binary from a different GitHub owner via unpinned curl|bash or cargo --git. There is no clear exfiltration or credential theft behavior, so this is not malware, but it carries high supply-chain risk for a local execution hook.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:28 PM
Package URL
pkg:socket/skills-sh/oakoss%2Fagent-skills%2Fdestructive-command-guard%2F@516cdb3d64e3f428a20d697bd663032f683f1560