NYC

agent-os-framework

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

No malicious behavior is evident in the provided SKILL manifest and markdown templates. The content describes local repository scaffolding and generates markdown files under a .agent-os directory. Declared capabilities (Write, Read, Bash) are consistent with that purpose. No credential requests or outbound network flows are present in the artifact. Recommendation: safe to use from a supply-chain perspective as-is, but review the runtime implementation (the code that actually executes the Bash/Write actions) before granting filesystem or network permissions. Also validate any recommended third-party tooling (e.g., 'UV') independently.

Confidence: 80%Severity: 15%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:01 AM
Package URL
pkg:socket/skills-sh/vamseeachanta%2Fworkspace-hub%2Fagent-os-framework%2F@e8ff12cc1b48180e43479f541230df98c21299ee