bafishka

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Credential file access detected The provided fragment is a benign, high-level project description of bafishka. It outlines a multi-language tool (Fish shell + Rust Steel backend + SCI Clojure) with integration examples. No hard-coded secrets, credential collection, or suspicious network behavior is evident in this fragment. Some abstract conceptual elements are present, but they do not indicate malicious activity or misalignment with the stated purpose based on the information given. LLM verification: The provided documentation and examples show a legitimate REPL/eval tool that intentionally exposes powerful capabilities (arbitrary evaluation and filesystem access). There is no direct evidence in the supplied fragment of obfuscated or malicious code, hard-coded credentials, or automatic exfiltration. The main security concern is the intrinsic risk of arbitrary evaluation: if untrusted expressions are allowed, an attacker can read local files or perform network I/O with the privileges of the r

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 16, 2026, 11:37 AM
Package URL
pkg:socket/skills-sh/plurigrid%2Fasi%2Fbafishka%2F@f1371fb6e0c93e8421f4cbe6881484c8748f66b8