offload

Warn

Audited by Socket on Aug 21, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose matches delegation/orchestration, but it deliberately launches external builder agents with relaxed or disabled approval controls and supports arbitrary custom commands. There is no clear credential theft or exfiltration path in the skill itself, so it is not confirmed malware, but it is a high-risk autonomy and execution wrapper.

Confidence: 86%Severity: 81%
SecurityMEDIUM
dispatch.sh

This excerpt is a process/command orchestration script that injects $BLOCK and other config-derived values directly into commands executed via herdr/tmux/Terminal or (for custom) bash -c. It also intentionally disables/weakens tool safety controls using “dangerously-bypass-approvals-and-sandbox” (codex) and “dangerously-skip-permissions” (claude). No clear exfiltration/keylogging/backdoor is visible, but the direct input-to-execution wiring and permission bypass create a high security risk if any of the inputs (CANDIDATES/custom/BLOCK/env/config) are attacker-influenced.

Confidence: 66%Severity: 72%
Audit Metadata
Analyzed At
Aug 21, 2026, 08:03 PM
Package URL
pkg:socket/skills-sh/borkweb%2Fskills%2Foffload%2F@d6cdb5683f58c580823a607a91da6bb33904cf732ed811771995881c3e8704a7
Security Audit — socket — offload