project-watchdog

Warn

Audited by Socket on Aug 26, 2026

3 alerts found:

Securityx2Anomaly
SecurityMEDIUM
SKILL.md

The skill is purpose-consistent for a cross-project GitHub watchdog, but its operational footprint is high-risk: unattended cron execution, untrusted GitHub content driving local/Tau commands, credential-bearing subprocesses, and optional automatic pushes/closures. This looks more like a powerful automation skill than malware, but it should be treated as suspicious/high-risk due to autonomy and content-to-execution exposure.

Confidence: 86%Severity: 72%
SecurityMEDIUM
scripts/watchdog/handlers.py

The code implements a legitimate-looking GitHub/Tau project watchdog with substantial repository and issue-management capabilities. No clear malware payload, credential theft, reverse shell, cryptomining, or suspicious hardcoded network destination is present. However, closure comments control file paths that are read from disk and exposed to an external provider prompt, creating a concrete arbitrary local-file disclosure risk. Git pushes and optional direct landing to main are high-impact intended actions that require trusted configuration and agent isolation. The apparent syntax corruption also prevents execution as shown.

Confidence: 96%Severity: 72%
AnomalyLOW
scripts/watchdog/service.py

The code is a service restart and health-check helper. It contains potentially dangerous shell execution because configuration-controlled restart_cmd and health_check are passed to bash -lc without validation. This is a security risk when configuration is untrusted, but the fragment provides no direct evidence of malicious intent or malware. The code is also incomplete as supplied.

Confidence: 98%Severity: 68%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:03 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fproject-watchdog%2F@ffaef67f800775d600b1fc28af330c4545ebea35708c6c2bd21effb5a102457a
Security Audit — socket — project-watchdog