modify-self

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The provided fragment documents a high-privilege 'modify-self' capability that permits an agent to alter its own code, personality, cron jobs, skills, and OS files. While the snippet only shows a benign read of local documentation, the declared ability to write those sensitive targets is a significant security risk. Without explicit scoping, human approval, integrity checks, and logging, this capability can enable persistence, concealment, and credential/data theft. Treat this skill as dangerous by default: require strict controls, manual review, and implementation safeguards before deployment.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:13 AM
Package URL
pkg:socket/skills-sh/winsorllc%2Fupgraded-carnival%2Fmodify-self%2F@cc8e3a75f8b4e7f27c90e1b278b4bae7c8206dda