ssh

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s main SSH capability is purpose-aligned, and its only dependency appears to be a legitimate open-source npm package. However, it enables powerful remote command execution, stores or consumes sensitive SSH credentials from local files, uses an unpinned dependency, and adds an unnecessary chain of other skills/subagents that expands trust. No clear exfiltration or malicious routing is shown, but the footprint is higher-risk than a narrowly scoped SSH helper.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
Apr 20, 2026, 08:31 AM
Package URL
pkg:socket/skills-sh/anentrypoint%2Fplugforge%2Fssh%2F@085e161d2dd1fd66bdf2c575bd659f9a220d051a
Security Audit — socket — ssh