windows-qa-engineer
Warn
Audited by Socket on Sep 5, 2026
1 alert found:
SecuritySecurityscripts/skill_installer.py
MEDIUMSecurityMEDIUM
scripts/skill_installer.py
This code is a manifest-driven installer/configurator that performs high-risk supply-chain actions: it can clone arbitrary git repositories and run pip installs based on install.yaml, and it can execute arbitrary Python code from manifest['verify']['script'] via `python -c`. There are no direct signs of covert malware (no obfuscation or hardcoded exfiltration), but the execution model makes it a likely target/vehicle for supply-chain sabotage if the manifest or referenced dependencies are attacker-controlled. Overall: medium-to-high security risk due to arbitrary code execution and untrusted dependency installation.
Confidence: 72%Severity: 70%
Audit Metadata