monitor-skills

Fail

Audited by Socket on Mar 17, 2026

2 alerts found:

Obfuscated FileAnomaly
Obfuscated FileHIGH
probes/model_health.py

No evidence of remote backdoors, data exfiltration, or obfuscated/malicious payloads in the inspected file. The module is an operational automation tool that legitimately reads local model/feedback artifacts and can trigger local training scripts. The primary security concern is local arbitrary code execution risk: importing modules from a repository-controlled SKILLS_DIR and executing repository or filesystem-provided run.sh scripts if thresholds are met. Mitigations: run only in trusted environments, ensure SKILLS_DIR and ~/.pi paths are write-protected, audit run.sh and imported common.* modules, and keep dry_run=True unless execution is intentionally enabled and reviewed.

Confidence: 98%
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent for drift monitoring, but its footprint goes beyond simple monitoring into autonomous cross-project modification and orchestration of other local skills. The absence of external endpoints and credentials keeps malware likelihood low, yet the non-interactive repair loop and transitive trust chain make it a medium security risk.

Confidence: 83%Severity: 61%
Audit Metadata
Analyzed At
Mar 17, 2026, 06:41 AM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fmonitor-skills%2F@085c6c0efee6538d8a3628754b1122c66893bd04
Security Audit — socket — monitor-skills