skill-security

Fail

Audited by Socket on Apr 18, 2026

1 alert found:

Malware
MalwareHIGH
references/command-blacklist.md

The provided content is overwhelmingly indicative of malicious intent and contains explicit, directly executable host-destruction and compromise techniques: download-and-execute RCE (curl/wget | bash/sh and eval of downloaded content), reverse shells, privilege escalation via SUID, fork bomb/DoS, firewall disabling, and sensitive credential targeting. This is not benign dependency code and should be treated as malware in a supply-chain context.

Confidence: 94%Severity: 100%
Audit Metadata
Analyzed At
Apr 18, 2026, 08:58 PM
Package URL
pkg:socket/skills-sh/fatih-developer%2Ffth-skills%2Fskill-security%2F@70dd3f058ecdf6de040f70dcbba56e0a2009601b
Security Audit — socket — skill-security