learn-artist

Fail

Audited by Socket on Mar 17, 2026

2 alerts found:

Obfuscated FileSecurity
Obfuscated FileHIGH
run.sh

Overall, Report 1 provides the most comprehensive assessment among the three, correctly highlighting the multi-layered risk surface: external data sources, Dockerized processing, and internal monitoring communications. While the workflow itself is not inherently malicious, the integration points create significant supply-chain and operational security risks. Recommended mitigations include input validation and sanitization for all artist entries, narrowing and validating external tool outputs, restricting network exposure of the internal TASK_MONITOR_API, signing/verifying downloaded artifacts, implementing integrity checks for downloaded content, and auditing the Docker images and mounted volumes. Consider introducing a formal risk assessment and trust boundary model for all external scripts and dependencies.

Confidence: 98%
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s core purpose is coherent with media/RVC training, but its execution trust is disproportionate because it runs a third-party Docker image and depends on loosely verified external artifacts. No direct credential theft is evident, yet the black-box container, mutable tag pull, composed-skill trust chain, and autonomous download/execute behavior make this a high security-risk skill.

Confidence: 87%Severity: 81%
Audit Metadata
Analyzed At
Mar 17, 2026, 06:40 AM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Flearn-artist%2F@c91e287c456b63bacd1a6c15a18b75cf905142c2
Security Audit — socket — learn-artist