b0

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core delegation purpose is coherent, but it meaningfully expands trust boundaries by installing external tooling, reading stored Box0 credentials from disk, sending repo content to external agents/servers, enabling cron-based unattended delegation, and instructing transitive skill installation. The main concern is security risk and over-broad agent delegation surface, not confirmed malware.

Confidence: 82%Severity: 68%
Audit Metadata
Analyzed At
Mar 26, 2026, 06:54 PM
Package URL
pkg:socket/skills-sh/risingwavelabs%2Fskills%2Fb0%2F@a8e7cc66559ac615025845b07643b3135e27ab7d