undetectable-ai

Fail

Audited by Socket on Feb 14, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Installation of third-party script detected This repository implements a text-analysis and transformation tool expressly designed to evade AI-detection systems. The code fragments shown are consistent with benign pattern-based text processing and do not display direct signs of malware (no obfuscation, hardcoded credentials, or exfiltration endpoints). However, the project’s explicit abusive purpose (bypassing detectors) and the inclusion of Shell and npm/npx flows substantially increase supply-chain and operational risk. From a security standpoint: treat the project as high ethical risk; do not run installs or scripts in trusted environments without auditing package.json, install scripts, and full source code. If the tool must be used for research, audit dependencies, remove Shell permissions, and run in a sandboxed environment. LLM verification: From a technical supply-chain and malware perspective the provided materials show low likelihood of embedded malware: processing is local, there are no network sinks or dynamic code-execution patterns in the fragment, and no hardcoded secrets or obfuscation are apparent. However, the package is explicitly designed to help users evade AI-content detectors and therefore is high-risk from an ethical and abuse perspective (facilitates plagiarism and evasion of detection). Operational recommendation:

Confidence: 98%Severity: 90%
Audit Metadata
Analyzed At
Feb 14, 2026, 04:47 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fundetectable-ai%2F@e5cb73aad3782522b3d02804781d67c20e153965