swain-doctor

Warn

Audited by Socket on May 7, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
scripts/swain-doctor.sh

Overall, this appears to be a repository health-check/auto-repair script, not a typical malware sample. However, it contains a critical dynamic-execution sink: check_platform_dotfolders uses eval on a value read from platform-dotfolders.json (.detection). If that JSON is attacker-controlled (or comes from a compromised dependency/source), this can lead to arbitrary command execution when the script runs. Additionally, the script sources a repo-relative legacy library (supply-chain exec risk) and performs destructive filesystem modifications (rm -rf) and symlink rewrites in execution paths (bin/ and .agents/bin/). No obvious network exfiltration or reverse-shell behavior is present in this fragment.

Confidence: 78%Severity: 70%
SecurityMEDIUM
SKILL.md

SUSPICIOUS due to transitive third-party skill installation via `npx skills add obra/superpowers`, which extends trust beyond the stated local doctor role. Otherwise the skill is largely coherent and proportionate: it performs local repo health checks and repairs without evident exfiltration or credential forwarding.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
May 7, 2026, 09:48 PM
Package URL
pkg:socket/skills-sh/cristoslc%2Fswain%2Fswain-doctor%2F@a530ab969a85ff1d1723f8d8d479ea9a46a59daa