last30days

Fail

Audited by Socket on Feb 12, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The feature's goal (research community discussion over the past 30 days) is reasonable and the document describes a plausible workflow. However, automatic API key detection combined with broad privileges (Bash, Read, Write) and reliance on an external, unreviewed local script creates a notable supply-chain and credential-exfiltration risk. The fragment itself contains no explicit malicious payloads, but its operational design is unsafe by default: it should require explicit user-provided API keys, list and limit which files/vars may be read, drop unnecessary privileges (avoid shell/write if not needed), and include verifiable checksums or source code for the invoked script before trusting it. I recommend treating the script as untrusted until audited, removing automatic credential discovery, and narrowing allowed-tools.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Feb 12, 2026, 11:12 PM
Package URL
pkg:socket/skills-sh/trailofbits%2Fskills-curated%2Flast30days%2F@424a4460e63fce11d6923435a5ebcba1b08b8b18