modern-python

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill's stated purpose (bootstrapping and standardizing a modern Python toolchain) is coherent with the capabilities it documents. The primary security concern is the recommended curl | sh installation of uv (astral.sh installer) — a classic download-and-execute supply-chain pattern that significantly raises risk if the remote script or its hosting were compromised. Additional risk comes from centralizing trust in the uv/astral-sh ecosystem and automated CI/dependabot flows that will fetch and execute third-party code. There are no explicit credential-harvesting routines, obfuscated payloads, or direct exfiltration endpoints in the provided text. Overall this is not demonstrably malware, but it is a supply-chain risk and should be treated with caution: prefer pinned installers/checksums, audit the installer script, pin GitHub Actions to commit SHAs, and avoid blindly running curl | sh.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 3, 2026, 08:46 AM
Package URL
pkg:socket/skills-sh/oimiragieo%2Fagent-studio%2Fmodern-python%2F@145d9280245352cc45ad2e55532d3a055594f596