skill-forge-base

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
tmp_old_server.js

The payload demonstrates extensive obfuscation combined with a complex server architecture that processes quiz data, AI prompts, and analytics while enabling spawning of external processes and broad data exfiltration paths. The convergence of dynamic code execution potential, insecure data handling, and backdoor-like prompts strongly indicates a malicious or dangerously insecure supply-chain component. Immediate remediation should treat this as high risk: remove from dependencies, restrict file/command access, avoid dynamic requires and CLI spawns, implement strict input validation and parameterized data access, and conduct a full provenance/security review of all embedded templates and prompts.

Confidence: 92%Severity: 92%
Audit Metadata
Analyzed At
Feb 16, 2026, 12:00 PM
Package URL
pkg:socket/skills-sh/zjfls%2Fzhoujie-claude-skills%2Fskill-forge-base%2F@4c4f79bfc12968ba20d25c48de877bc52d9f081a