agent-performance-benchmarker

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This appears to be a legitimate, feature-rich benchmarking and adaptive tuning agent for distributed consensus protocols. The primary risks are operational: (1) autonomous application of configuration changes to live systems without explicit per-change authorization; (2) potential exfiltration of detailed telemetry and topology via mcpTools and persistent storage if those endpoints are external or untrusted; and (3) potential for resource exhaustion or DoS by aggressive workload generation. There are no clear signs of obfuscation or direct malicious backdoors in the code fragment itself, but the security posture hinges on the trustworthiness and access controls of referenced platform components (mcpTools, TimeSeriesDatabase, SystemMonitor, PerformanceModel). Recommended mitigations: require explicit user approval for each optimization, restrict mcpTools endpoints to trusted internal services, enforce conservative defaults and global concurrency/rate limits for load generation, and audit the implementations of referenced abstractions.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 1, 2026, 04:35 PM
Package URL
pkg:socket/skills-sh/ruvnet%2Fruflo%2Fagent-performance-benchmarker%2F@481ba63e8d96dc117f740f007055566e43a8a27c