boss

Warn

Audited by Socket on May 19, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

该 Skill 的广泛读写、命令执行、测试/部署能力与“全自动研发流水线”目的基本一致,因此不像伪装型窃密技能;但其权限面非常宽,且主动发现并调用其他 Skill/插件带来明显的转移信任与间接提示注入风险。总体应判为 SUSPICIOUS:高权限自动化编排工具,非确认恶意,但安全风险中高。

Confidence: 82%Severity: 66%
AnomalyLOW
hooks/hooks.json

No explicit malware indicators (secrets, obfuscation, suspicious network destinations) are present in this configuration fragment. However, it establishes a high-impact execution pathway by dynamically running local JavaScript hook scripts via a command runner at sensitive pipeline lifecycle events. Security therefore hinges on the integrity and correctness of `scripts/hooks/*.js` and the `boss` hook runner; review and verify those implementations and their supply-chain integrity to rule out exfiltration or tampering. Overall: likely guardrail orchestration, with structural supply-chain risk due to delegated script execution.

Confidence: 55%Severity: 60%
Audit Metadata
Analyzed At
May 19, 2026, 05:19 AM
Package URL
pkg:socket/skills-sh/echoVic%2Fboss-skill%2Fboss%2F@18783839b5dac1ed106db4903fcaacc390e3a97a
Security Audit — socket — boss