entrepreneur-skill

Warn

Audited by Socket on May 13, 2026

1 alert found:

Anomaly
AnomalyLOW
persona.json

No direct malware logic is present in this snippet because it is a configuration/manifest. The primary concern is security posture: it explicitly authorizes high-risk tools (Bash via npm/npx/curl, plus WebFetch and Read/Write) and enables remote gateway/A2A integrations and dynamic external skill references. If the hosting runtime does not strongly sandbox execution, restrict command construction from untrusted inputs, and verify/provision external skills with integrity controls, the configuration could facilitate remote execution or data movement. This should be reviewed together with the runtime’s enforcement, network egress limits, and provenance verification for referenced skillssh: resources.

Confidence: 62%Severity: 60%
Audit Metadata
Analyzed At
May 13, 2026, 12:39 PM
Package URL
pkg:socket/skills-sh/acnlabs%2Fopenpersona%2Fentrepreneur-skill%2F@83d1247e83c96bad1433f343f07436eaae12033b