run-with-it

Warn

Audited by Socket on May 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's core purpose matches orchestration, but it grants very high operational authority. The biggest risks are autonomous real-world actions, sandbox-bypassing child execution, and indirect prompt injection from GitHub content into write/exec-capable sub-agents. I do not see clear evidence of credential theft or covert exfiltration, so this is high-risk orchestration rather than confirmed malware.

Confidence: 88%Severity: 83%
Audit Metadata
Analyzed At
May 14, 2026, 08:38 AM
Package URL
pkg:socket/skills-sh/chanakya-net%2FAI-Skills%2Frun-with-it%2F@b4e596670bf84c4ff46b39348a4c1d610083e425