pipeline

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is an orchestration helper for sequential agent pipelines and is plausible for its stated purpose. However, its operational footprint is broader than necessary and contains several risky elements: it permits broad filesystem and shell capabilities, persists full stage outputs (which can include secrets), forwards prior outputs to later agents (credential forwarding), and — most importantly — prescribes a destructive rm -rf fallback that can delete user data. These behaviors are disproportionate and dangerous for a pipeline skill unless tightened (limit file reads to a safe workspace, sanitize outputs before forwarding/persisting, remove destructive fallback or replace with safe deletion limited to created resources). Overall, I assess low probability of intentional malware (no obfuscation or remote-download patterns), but moderate to high security risk due to destructive and overly-broad actions that could lead to data loss or credential exposure.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 25, 2026, 10:12 AM
Package URL
pkg:socket/skills-sh/reinamaccredy%2Fmaestro%2Fpipeline%2F@1e5cb5fea9eb82bb61790a8529a518bf556fda56