ai-ml-expert

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

No direct malware is present in the provided source text, but the skill contains high-risk operational instructions: a mandatory Memory Protocol that reads/writes agent-local memory and a broad set of powerful tools (Bash, Read/Write/Edit, WebSearch). These allow sensitive data (system prompts, credentials) to be read and persisted and permit arbitrary shell execution at runtime. The core risk is information disclosure and potential for destructive or exfiltrative actions if the runtime enforces the declared capabilities without human oversight. I recommend removing or gating the Memory Protocol, narrowing tool permissions, sandboxing file access, and adding explicit user confirmation and auditing for any Bash or network operations.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Mar 18, 2026, 02:00 AM
Package URL
pkg:socket/skills-sh/oimiragieo%2Fagent-studio%2Fai-ml-expert%2F@103991fa720a88513f1aa507f7e04f704aca22bd