runtime-python-toolchain
Audited by Socket on Jun 17, 2026
2 alerts found:
Anomalyx2SUSPICIOUS: the core purpose is legitimate, and the host checks/APT installation are proportionate, but the mandatory rerouting of pip to a third-party Aliyun mirror plus `PIP_TRUSTED_HOST` creates an unnecessary trust and integrity risk for a generic Python toolchain skill. No clear credential theft or exfiltration is present, so this is not malicious, but the package-source override makes the skill riskier than its stated purpose requires.
This manifest does not contain direct malicious payloads, but it significantly elevates execution capability by allowing unrestricted (allow_all) usage of MCP shell primitives and Docker compose execution. In a supply-chain setting, that governance/control-plane weakness can enable arbitrary command or container execution if upstream workflow inputs or command derivation are compromised or attacker-influenced. Review and tighten tool approval and/or restrict command/service allowlists.