compile-analysis

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Instruction directing agent to run/execute external content All findings: [CRITICAL] command_injection: Instruction directing agent to run/execute external content (CI011) [AITech 9.1.4] [CRITICAL] command_injection: Instruction directing agent to run/execute external content (CI011) [AITech 9.1.4] The provided fragment is a coherent, purpose-aligned compilation analysis skill for ACE Engine, focusing on measuring compile performance and header dependencies using standard, local tooling. It avoids sensitive data handling or network activity and supports reproducible benchmarking. Overall, it appears safe and appropriate for its stated goals. LLM verification: Functionally, this is a legitimate compile-analysis utility that extracts and instruments compilation commands and parses preprocessed files for header dependency trees. The primary security concern is operational: executing extracted/enhanced compilation commands or the generated standalone scripts can lead to arbitrary code execution if the build files, ninja rules, or toolchain are untrusted or have been tampered with. No direct indicators of malware, secrets harvesting, or network exfiltrati

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 16, 2026, 10:18 PM
Package URL
pkg:socket/skills-sh/openharmonyinsight%2Fopenharmony-skills%2Fcompile-analysis%2F@ffa7fb35ce3afd639cef4741758331d8985e5d94