adk-engineer

Warn

Audited by Socket on Aug 11, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/validate_agent.py

No direct malicious payload is evident in the validator logic itself (no networking, exfiltration, or credential handling). However, the module dynamically imports and executes the supplied agent file via spec.loader.exec_module, creating an arbitrary code execution risk whenever the input agent file is not strictly trusted and sandboxed/allowlisted. This is the primary security concern for this code fragment.

Confidence: 76%Severity: 74%
Audit Metadata
Analyzed At
Aug 11, 2026, 05:09 PM
Package URL
pkg:socket/skills-sh/cor-incorporated%2Fclaude-code-skills%2Fadk-engineer%2F@7d9ad9675afbf5baf6fc908464f77c59a3b2e6bd8b24e3931c59c9875514b4a3
Security Audit — socket — adk-engineer