monitor-opportunities
Audited by Socket on Aug 26, 2026
3 alerts found:
Anomalyx3SUSPICIOUS. The stated purpose is plausible, but the skill is internally inconsistent about whether it may autonomously submit applications, and it composes broader email/LinkedIn/mailbox capabilities than a Stage 0 research-only monitor should need. Install trust looks mostly benign, but the autonomy contradiction and untrusted-content processing with Bash/Write make the overall skill medium-high risk.
The fragment appears to be a legitimate orchestration CLI with explicit gating and audit receipts, not overt malware. It does perform significant network, browser, GitHub, Memory, Buzz, Docker, and application-related operations when invoked with the relevant options. The main security concern is execution of scheduler-receipt-derived text through shell=True without cryptographic authentication of the receipt, creating a potential command-execution path for tampered local scheduler data. Imported integration modules also require separate review because they contain the actual external-action implementations.
No clear evidence of malware or deliberate sabotage is present. The code implements report synchronization and bounded memory-service recall. Security review is warranted because an unrestricted memory_url can redirect sensitive report data to an arbitrary HTTP host and may permit SSRF, and because this module does not provide authentication or TLS guarantees. The apparent incomplete class and function syntax should be corrected or verified against the complete source.