retry-utils

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The provided content is documentation for a retry helper that intentionally executes arbitrary shell commands with configurable retry/backoff behavior. The document itself contains no direct malicious code, downloads, or exfiltration endpoints. However, because the core capability is to run arbitrary commands and to pass through environment variables, misuse or a malicious/buggy implementation of retry.sh could lead to credential exposure, unintended network activity, or supply-chain impact (e.g., automatically retrying package installs). Without the actual script implementation, there is moderate operational risk: treat any installation or use of retry.sh as sensitive, review the script source for unsafe shell handling, and avoid running untrusted commands through it. Overall: no confirmed malware in the documentation, but the capability is powerful and can be dangerous in practice if misused or if the implementation is malicious or insecure.

Confidence: 85%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:13 AM
Package URL
pkg:socket/skills-sh/winsorllc%2Fupgraded-carnival%2Fretry-utils%2F@ad954731263511bfe2e521e1817bdb14b9af65db