os-eval-runner

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s core local evaluation purpose is plausible, but its actual footprint is broader than necessary. Autonomous mutation/commit/push behavior, transitive skill installation, destructive cleanup commands, and forwarding project content to external proposer CLIs make the scope disproportionate to a stateless evaluator.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Apr 3, 2026, 06:10 PM
Package URL
pkg:socket/skills-sh/richfrem%2Fagent-plugins-skills%2Fos-eval-runner%2F@3075eb11d257304b091ae1ce6c4e53adb775787e