agent-sona-learning-optimizer

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The analysis indicates coherent intent for an adaptive-learning agent, but with notable supply-chain risks due to runtime downloads, alpha-tagged dependencies, and unusual package identifiers. Without rigorous integrity checks (version pinning, hashes, signatures) and trusted registry controls, the dynamic orchestration path poses elevated risk. Recommend enforcing strict integrity verification, using pinned, audited packages, restricting external hook execution to trusted registries, and performing pre-use audits of the external tooling. Overall risk: moderate-to-high given dynamic code execution paths, though no explicit malware detected in the provided fragment.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 1, 2026, 04:33 PM
Package URL
pkg:socket/skills-sh/ruvnet%2Fruflo%2Fagent-sona-learning-optimizer%2F@365db85d5a6fdebd68710750e6d909219421933b