aggressively-cleanup-skills
Warn
Audited by Socket on Aug 23, 2026
1 alert found:
AnomalyAnomalyscripts/archive.mjs
LOWAnomalyLOW
scripts/archive.mjs
No direct indicators of embedded malware (no network/exfiltration, no code execution primitives, no obfuscated payloads). However, the script performs high-impact filesystem operations (rename/unlink/symlink creation) using paths derived from locally parsed JSON (audit.json) and writes output based on an environment-controlled directory (SKILL_AUDIT_DIR) without validation. If an attacker can tamper with audit.json/keep-list.json or influence SKILL_AUDIT_DIR, this can enable path traversal/targeting abuses and unintended filesystem changes within the executing user’s permissions.
Confidence: 62%Severity: 52%
Audit Metadata