NYC

r-expert

Warn

Audited by Socket on Feb 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This document is a benign instructional skill describing R workflows and example code. It contains expected sources/sinks for such a skill (local files, DB, and example API request) and no hardcoded secrets, obfuscated code, or malicious routines. The main risk is operational: the declared allowed-tools entry ('Bash(R:*, Rscript:*)') is broad and, if actually granted to an executing agent, would allow arbitrary shell/Rscript execution and therefore could be abused to read sensitive files or exfiltrate data. That capability is disproportionate for a static documentation skill unless strictly sandboxed. Overall: no direct malware found in the content, but exercise caution around runtime tool permissions.

Confidence: 80%Severity: 15%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:51 PM
Package URL
pkg:socket/skills-sh/personamanagmentlayer%2Fpcl%2Fr-expert%2F@affd77d5f40253e78448f48f7fd5174e73a91274