python-executor

Warn

Audited by Socket on Jun 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s remote Python-execution behavior is broadly aligned with its stated purpose and appears tied to official inference.sh infrastructure, so this is not strong evidence of malware. Risk comes from transitive skill installation, moderate supply-chain hygiene, broad bash/CLI scope, and the fact that arbitrary code and scraped data are routed through a remote execution service.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 19, 2026, 02:15 AM
Package URL
pkg:socket/skills-sh/halt-catch-fire%2Fskills%2Fpython-executor%2F@81e4b2f65cdeb73772a9c06be4aef10b5c2c21d3bdc58b01541e0a5d047bfb87
Security Audit — socket — python-executor