vm0

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core VM0 self-management behavior is broadly consistent with the stated purpose and uses same-org docs/package sources, so this is not strong evidence of malware. The main risk is disproportionate trust expansion: it instructs the agent to self-modify, redeploy, and install additional third-party skills discovered via skills.sh, creating a transitive capability and data-access chain that exceeds a narrowly scoped config-management skill.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Mar 26, 2026, 05:16 PM
Package URL
pkg:socket/skills-sh/vm0-ai%2Fvm0-skills%2Fvm0%2F@c895b8239bda49a29646d98b56708c01a0ce4557