vibe
Audited by Socket on May 30, 2026
14 alerts found:
Anomalyx10Securityx2Obfuscated FileMalwareNo direct malicious activity is evident in the provided wrapper fragment (no exfiltration, credential theft, or overt backdoor logic). However, the script is a high-impact orchestrator that can trigger external npm-based installation and executes PowerShell with -ExecutionPolicy Bypass, while adapter-provided metadata can influence target-root resolution via indirect environment expansion. The security posture therefore depends heavily on the integrity and safety of referenced repository scripts (install.sh/check.sh/bootstrap/setup .ps1) and the trustworthiness of adapter metadata. Overall: low direct malware likelihood in this fragment, but moderate supply-chain execution risk.
SUSPICIOUS: the core scientific-review guidance is benign and internally coherent, but the skill expands scope by defaulting to a separate schematics skill that can execute local Python and send prompts/content plus an API key to OpenRouter. This is not clearly malicious, yet the transitive skill dependency and third-party data flow are disproportionate to the stated purpose of scientific critical thinking alone.
No direct malicious behavior is visible in this fragment (it contains only packaging/resolution configuration). The security-relevant concern is that it bundles and enables an internal hidden skill corpus under a canonical root while exposing only wrapper skills publicly, and it includes PowerShell host policy/config that could govern execution in downstream components. Inspect the contents of bundled/skills and the runtime interpretation of SKILL.runtime-mirror.md and powershell-host-policy.json to rule out payloads.
SUSPICIOUS: the wrapper's stated purpose is coherent, but it outsources all substantive behavior to a separate `vibe` runtime whose install and release trust are only partially verifiable. No direct credential harvesting or malicious exfiltration is shown here, yet the delegated execution surface and lack of strong provenance controls make the skill medium risk.
SUSPICIOUS due to distribution and transitive-install trust issues, not because of the stated UX-research functionality. The visible capability set is coherent and proportionate, but provenance is incomplete and the actual script code/install artifacts were not provided, so risk remains medium until the repository contents and release path are verified.
SUSPICIOUS. The skill's overall purpose and capabilities mostly align with scientific slide creation, and there is no sign of overt malware or deceptive installers. The main concern is data-flow integrity: research content, attached figures, and prompts are routed through OpenRouter using an external API key instead of a first-party Google path, creating a moderate third-party exposure risk for sensitive unpublished materials.
SUSPICIOUS: the local compat loop is broadly consistent with the stated purpose, but the optional open engine expands scope to an undocumented external CLI/backend with unclear provenance and data flows. Risk is driven more by execution trust and autonomy than by confirmed malicious behavior.
SUSPICIOUS: the core research-lookup behavior is mostly coherent and not overtly malicious, but the skill broadens trust by routing queries and credentials through OpenRouter, references an unverified secondary skill for schematics, and requests broader agent tools than a lookup-only function needs. Risk is driven more by third-party credential/data routing and transitive trust than by confirmed malware behavior.
SUSPICIOUS: the stated purpose is plausible and the visible footprint is mostly local, but the skill asks the agent to run an unverifiable local PowerShell script with ExecutionPolicy Bypass. There is no evidence of credential theft or exfiltration from the provided material, yet install/execution trust is weaker than expected for a simple command router.
SUSPICIOUS: The main report-writing capability is coherent, but the skill overreaches by making a separate schematic skill mandatory for all reports, creating a transitive trust and privacy risk for sensitive clinical data. No confirmed malware or direct exfiltration is present in the provided text, but the external dependency and unclear PHI handling make the footprint not fully proportionate to the stated purpose.
SUSPICIOUS: The skill’s purpose is coherent, and its credentials/endpoints are mostly proportionate, but its core install-and-execute path relies on a third-party personal GitHub repository rather than an evidently publisher-controlled source. This creates a medium-high supply-chain and credential-forwarding risk, though there is not enough evidence here to call it malicious.
BENIGN with notable supply-chain caveat. The skill’s behavior is coherent with a local evidence-retrieval purpose and shows no credential harvesting or exfiltration, but the optional use of a vendored local Python runtime is not publicly verifiable from the provided evidence and materially increases execution trust risk.
Current dataset contains no executable code to assess for malware, vulnerabilities, or anomalous behavior. A precise security assessment requires the actual source files (e.g., validation logic, target coverage tests, and conftest routines) to identify potential hard-coded secrets, unsafe file operations, or unintended mutations. Recommend providing the codebase excerpt or repository snapshot covering the validated review findings, particularly focusing on canonical validation semantics, target coverage logic, and any test-time file-system interactions mentioned in the acceptance criteria.
SUSPICIOUS due to transitive skill installation and support for arbitrary GitHub repos, not because of clear malware behavior. Curated OpenAI-hosted installs are coherent and same-org, but the skill’s footprint expands trust to unreviewed third-party skills fetched from mutable refs and written into the agent’s skills directory.