monitor-misuse

Warn

Audited by Socket on Aug 26, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose mostly matches the behavior, but the skill combines untrusted event ingestion, LLM-generated proposals, scheduled autonomous execution, and local file modification. The main concern is not overt malware but self-modifying behavior with insufficient guardrails and unclear execution provenance.

Confidence: 84%Severity: 63%
AnomalyLOW
scripts/apply.py

The code appears intended as a local correction-management utility, not malware. It communicates with a local Unix socket and modifies registered guard files. The main security concern is unsafe generation of Python source from unvalidated correction data, combined with automatic overwriting of files. A compromised or malformed memory-service record could cause source corruption or code injection on later module import. The fragment also appears syntactically invalid as supplied.

Confidence: 96%Severity: 62%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:02 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fmonitor-misuse%2F@eb038aa51b7481f167e681d90b405188fa75f945244377183e0b0fe6b6ca31f0
Security Audit — socket — monitor-misuse