evaluate

Warn

Audited by Socket on Oct 5, 2026

3 alerts found:

Anomalyx3
AnomalyLOW
pipeline/LOOP-PROMPT.md

The fragment describes an evaluation-and-maintenance workflow, not package code. It contains high-impact repository and command-execution instructions, especially permission bypass and pushing changes to main, which should only be performed in an authorized, controlled environment. The visible content does not establish malicious package behavior; the opening is truncated, so assessment is limited to the shown portion.

Confidence: 97%Severity: 62%
AnomalyLOW
LOOP.md

The excerpt describes a plugin evaluation and publishing workflow. It contains no clear evidence of malware, but it directs execution with permission protections bypassed and uses broad staging, direct pushing, and variable-based recursive cleanup. These are consequential operational risks that should be guarded with review and validated paths.

Confidence: 94%Severity: 56%
AnomalyLOW
OPENCLAW-SETUP.md

No direct malware is evident in this documentation. It describes a high-privilege autonomous workflow that executes repository-provided instructions and pushes agent-generated changes. Review LOOP-PROMPT.md and restrict credentials and execution permissions before deployment.

Confidence: 96%Severity: 58%
Audit Metadata
Analyzed At
Oct 5, 2026, 01:57 AM
Package URL
pkg:socket/skills-sh/careerhackeralex%2Fvisualize%2Fevaluate%2F@3942ec8bc9720e3d2a5bded4adcd93914afe9b61d8da66d92ed06daa96677073