poc-calc

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose is to reproduce a shell injection vulnerability, which is exploit-oriented and not a normal benign skill function. The provided content is very small and shows no credential theft, exfiltration, or external supply-chain abuse, so this is not confirmed malware, but it is a high-risk offensive/security-testing skill with disproportionate intent.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Mar 13, 2026, 08:44 PM
Package URL
pkg:socket/skills-sh/sonix03%2Fskills-update-rce-poc%2Fpoc-calc%2F@7030bdd3b652fe1312627945fa0bc7884349a248