skill-comply

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/runner.py

No direct evidence of embedded malware, obfuscation, or credential theft within this Python module. However, it creates a substantial security-relevant execution surface by (a) executing scenario-provided setup commands via subprocess with only coarse executable-name allowlisting (arguments unchecked) and (b) invoking an external Claude agent with explicit Bash and write/edit tool permissions and access to the sandbox directory. If scenario definitions/prompts are untrusted or sandbox hardening is weak in the surrounding system, this module could enable high-impact command execution or unsafe filesystem operations within the runtime environment. Overall risk is driven by orchestration/delegation rather than in-module malicious code.

Confidence: 62%Severity: 66%
Audit Metadata
Analyzed At
Sep 12, 2026, 03:41 PM
Package URL
pkg:socket/skills-sh/eugene-ee%2Faffaan-m-ecc%2Fskill-comply%2F@2bb4fea99c3b94788a5e9f49f71b6814ce6fa6a2ec5cf104bb8ba1d4229a150b
Security Audit — socket — skill-comply