agents-md-manager

Fail

Audited by Socket on Feb 20, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Destructive bash command detected (rm -rf, chmod 777) Based on the provided skill documentation and scripts listing, there is no evidence of malicious code or hidden exfiltration. The capabilities and file read/write behavior are consistent with a legitimate AGENTS.md and Codex config management tool. Primary security consideration: the tool writes global config and rules which, if misused or populated with malicious endpoints or overly permissive rules, could alter agent runtime behavior — this is an operational risk to mitigate with user confirmation and review. No hardcoded secrets, no network exfiltration, and no obfuscation are present in the material reviewed. LLM verification: The selected Report 3 appropriately characterizes AGENTS.md management tooling, identifies an anomaly related to destructive commands in documentation, and provides justification for cautious trust. With targeted mitigations (secure execution context, explicit confirmations, and removal of risky command examples from operational pathways), the overall security posture remains acceptable for a developer-focused tooling scenario. Action: address the static command anomaly and enforce safe, auditab

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 20, 2026, 07:46 PM
Package URL
pkg:socket/skills-sh/tdimino%2Fclaude-code-minoan%2Fagents-md-manager%2F@ef04a40115a1197788c7c821c7ccca6bd6ba9f66