skill-as-a-service
Audited by Socket on Feb 16, 2026
1 alert found:
Malware[Skill Scanner] Natural language instruction to download and install from URL detected The skill's stated purpose aligns with its described capabilities and network endpoints (api.rebyte.ai). There is no direct evidence of malware or obfuscated code in the provided text. However, the capability to clone repositories into cloud VMs and to reuse workspaces that persist repo state and possible credentials is a notable supply-chain and data-exposure risk. This requires strong trust in the provider: sensitive repositories or secrets could be exposed, and reused workspaces could leak data between tasks. Recommend treating the package as potentially sensitive (review provider's security, data retention, isolation policies) before using with private code or secrets. LLM verification: This skill's functionality and documentation are consistent with its stated purpose (running coding agents in the cloud with a single API key). There is no direct evidence of malware or obfuscated malicious code in the provided content. However, the service necessarily transfers and persists user code, prompts, and repo contents to a third-party provider (api.rebyte.ai) and reuses VMs/workspaces — behaviour that can lead to unintended data exposure or persistent storage of sensitive material. Th