afrexai-agent-engineering
Audited by Socket on Feb 22, 2026
1 alert found:
Malware[Skill Scanner] Destructive bash command detected (rm -rf, chmod 777) This is a comprehensive, legitimate design and operations guide for AI agents (not executable/malicious code). No code-level malware or obfuscated payloads are present. Primary risks are operational: the guide encourages reading/writing of persistent memory files, scheduled outbound actions (cron/heartbeat), backups/exports, and explicit 'test vault access' steps — all of which create plausible data-exfiltration or credential-exposure vectors if guardrails are misapplied or an agent is compromised. Recommend enforcing technical controls (least privilege, automatic redaction, audited backups, human approval gates for any external messages or secret use) when implementing these patterns. LLM verification: This SKILL.md is a comprehensive, legitimate-looking operational playbook for building and running AI agents. It does not contain executable malicious code, obfuscated payloads, or remote download/execute instructions. However, it contains multiple high-risk operational patterns that could enable data leakage or destructive actions if implemented by an agent with broad filesystem and network privileges: automated writing/exporting of MEMORY.md and daily logs, instructions to test vault access, c