skill-eval

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/eval_runner.py

No clear supply-chain sabotage or embedded malware is evident in this fragment. The code primarily orchestrates sandbox copying, artifact capture, and subprocess execution of external tools (git and model/provider CLIs) with prompts derived from input JSON. The main security risk is command/subprocess execution driven by user-controlled inputs and the unresolved/truncated STUB_RUNNER_SOURCE in the provided snippet (which could contain additional execution logic outside this view).

Confidence: 62%Severity: 52%
Audit Metadata
Analyzed At
Aug 26, 2026, 01:35 AM
Package URL
pkg:socket/skills-sh/adhi-jp%2Fagent-skills%2Fskill-eval%2F@01008c0cb5ddba84be5828729836fdee2fff92b96217a1f32d9527246efc9374
Security Audit — socket — skill-eval