skill-security
Fail
Audited by Socket on Apr 18, 2026
1 alert found:
MalwareMalwarereferences/command-blacklist.md
HIGHMalwareHIGH
references/command-blacklist.md
The provided content is overwhelmingly indicative of malicious intent and contains explicit, directly executable host-destruction and compromise techniques: download-and-execute RCE (curl/wget | bash/sh and eval of downloaded content), reverse shells, privilege escalation via SUID, fork bomb/DoS, firewall disabling, and sensitive credential targeting. This is not benign dependency code and should be treated as malware in a supply-chain context.
Confidence: 94%Severity: 100%
Audit Metadata