ruanzhu

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the stated purpose is plausible, but the skill’s actual footprint depends on executing an opaque local Python script from a nonstandard path with no provenance, review, pinning, or integrity checks. Data flow appears local rather than overtly exfiltrative, so this is not confirmed malware, but the forced download/execute-style trust model and prohibition on inspection make it high security risk for a skill with a narrow stated purpose.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Mar 18, 2026, 09:58 PM
Package URL
pkg:socket/skills-sh/doccker%2Fcc-use-exp%2Fruanzhu%2F@13d217cc029b42bfa3b344ffed264074d359f606
Security Audit — socket — ruanzhu