aggressively-cleanup-skills

Warn

Audited by Socket on Aug 23, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/archive.mjs

No direct indicators of embedded malware (no network/exfiltration, no code execution primitives, no obfuscated payloads). However, the script performs high-impact filesystem operations (rename/unlink/symlink creation) using paths derived from locally parsed JSON (audit.json) and writes output based on an environment-controlled directory (SKILL_AUDIT_DIR) without validation. If an attacker can tamper with audit.json/keep-list.json or influence SKILL_AUDIT_DIR, this can enable path traversal/targeting abuses and unintended filesystem changes within the executing user’s permissions.

Confidence: 62%Severity: 52%
Audit Metadata
Analyzed At
Aug 23, 2026, 05:09 AM
Package URL
pkg:socket/skills-sh/edonadei%2Fskills%2Faggressively-cleanup-skills%2F@e88cf3c401dd9087626b89e2f5efb7d9dec6d778f8f8023b579fa16c9acc92ba
Security Audit — socket — aggressively-cleanup-skills