skill-lab
Audited by Socket on Mar 17, 2026
3 alerts found:
Securityx2AnomalySUSPICIOUS. The skill's broad self-modifying and transitive-install behavior is coherent with its stated 'symbiogenic skill creation' purpose, so it is not clearly deceptive malware. But its ability to generate, execute, promote, and schedule new capabilities across the agent environment creates a high-risk trust chain, and external model/data flows are underspecified.
This module is a pipeline orchestrator that discovers and executes run.sh scripts from skill directories. The code itself is not obviously malicious, but it inherently allows execution of arbitrary third-party code (run.sh) with full environment inheritance and filesystem access. The main risks are running untrusted scripts, leaking environment secrets to child processes, and trust on optional imported modules (memory/logging/predictor) that may perform network I/O or persistent storage. If skills or imported helper modules are untrusted or compromised (supply-chain attack), they can execute arbitrary commands and exfiltrate data. Recommend treating skill directories and optional dependencies as fully trusted before use, or running the orchestrator in a sandboxed environment and avoiding passing sensitive env vars.
This module is not itself obfuscated or containing obvious embedded malware, but it intentionally executes external 'skills' (their run.sh scripts) and dynamically imports and calls other project modules that may run arbitrary code. The major risk is supply-chain / execution-of-untrusted-code: if the skills directory or imported modules are attacker-controlled or contain malicious code, this orchestrator will execute them (either inside a Docker container with mitigations or directly on the host if Docker is unavailable). The auto-training and feedback logging features further increase risk because they import and execute additional modules which may perform network I/O or heavy computation. Recommend treating the skills_root and the imported modules as untrusted inputs: ensure skills are from trusted sources, run in fully isolated environments (prefer no local fallback), and audit imported helper modules. Overall, moderate to high security risk due to execution of untrusted scripts and dynamic imports.