skill-comply

Warn

Audited by Socket on Aug 12, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/runner.py

No direct evidence of embedded malware, obfuscation, or credential theft within this Python module. However, it creates a substantial security-relevant execution surface by (a) executing scenario-provided setup commands via subprocess with only coarse executable-name allowlisting (arguments unchecked) and (b) invoking an external Claude agent with explicit Bash and write/edit tool permissions and access to the sandbox directory. If scenario definitions/prompts are untrusted or sandbox hardening is weak in the surrounding system, this module could enable high-impact command execution or unsafe filesystem operations within the runtime environment. Overall risk is driven by orchestration/delegation rather than in-module malicious code.

Confidence: 62%Severity: 66%
Audit Metadata
Analyzed At
Aug 12, 2026, 10:27 PM
Package URL
pkg:socket/skills-sh/affaan-m%2Fecc%2Fskill-comply%2F@c6f02169bc177d67f2d3d567bf9d13d47b825f729deca0bbae2bbc32390699e4
Security Audit — socket — skill-comply