agent-swarm

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill presents a coherent and potentially valuable pattern for distributed, parallel task execution across multiple agent backends. However, there are notable security considerations: unverifiable or loosely specified dependencies, credential handling and token-loading guidance that could leak credentials, and potential shell-command injection surfaces in templated post-commands. Overall, the footprint is moderately risky (suspicious-to-benign). It would be considered acceptable with strict controls: pin and verify dependencies, avoid exposing tokens/logs, enforce strict input sanitization, and provide explicit access controls for outputs and timing data.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 07:02 PM
Package URL
pkg:socket/skills-sh/richfrem%2Fagent-plugins-skills%2Fagent-swarm%2F@e61988161bb37e286462e769721bb2b66c728135