execute-icebox

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill's stated purpose is coherent with its actions: it reviews task backlog state using a local task CLI and sub-agent delegation. The main concern is trust, not intent: it requires an external `agkan` binary whose provenance was not established and it adds transitive trust in other skills/sub-skills. No credential harvesting, exfiltration endpoint, stealth behavior, or disproportionate access is evident from this skill text, so this is better classified as suspicious/high-risk due to unverifiable dependency and transitive skill trust rather than malware.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 8, 2026, 06:44 AM
Package URL
pkg:socket/skills-sh/gendosu%2Fagkan-skills%2Fexecute-icebox%2F@6949bf149c0047858011bf1548de8547eb3067a2