NYC

hidden-folder-audit

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Destructive bash command detected (rm -rf, chmod 777) All findings: [CRITICAL] command_injection: Destructive bash command detected (rm -rf, chmod 777) (CI004) [AITech 9.1.4] [CRITICAL] command_injection: Destructive bash command detected (rm -rf, chmod 777) (CI004) [AITech 9.1.4] [CRITICAL] command_injection: Destructive bash command detected (rm -rf, chmod 777) (CI004) [AITech 9.1.4] [CRITICAL] command_injection: Destructive bash command detected (rm -rf, chmod 777) (CI004) [AITech 9.1.4] [CRITICAL] command_injection: Destructive bash command detected (rm -rf, chmod 777) (CI004) [AITech 9.1.4] No evidence of malware or network exfiltration. This Skill is a local repository cleanup/audit guide whose commands are appropriate for the stated purpose but include destructive operations (rm -rf, git rm --cached, find -delete, broad cp) and actions that could accidentally commit sensitive configuration files into VCS. Not malicious, but operationally risky if used without strict safeguards. Recommend stricter safety checks: require backups, use safer copy/move patterns, scan for secrets before migrating, avoid removing backup folders automatically, and prefer interactive or dry-run steps.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 16, 2026, 10:51 AM
Package URL
pkg:socket/skills-sh/vamseeachanta%2Fworkspace-hub%2Fhidden-folder-audit%2F@3f4038d9baae5ed66f13f3e2b3d0d4b1a64b10ba