python-sdk

Warn

Audited by Socket on Jun 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core Python SDK documentation is mostly coherent and uses an official pip package, but the skill also pushes unrelated/transitive skill installations and includes agent patterns that combine remote content ingestion with execution-capable tools. This is not confirmed malware, but it carries medium risk beyond a narrowly scoped SDK guide.

Confidence: 88%Severity: 61%
Audit Metadata
Analyzed At
Jun 19, 2026, 02:15 AM
Package URL
pkg:socket/skills-sh/halt-catch-fire%2Fskills%2Fpython-sdk%2F@c58f9892827bb6f6f21158925279afaa540d92565d6816554211a405168f2bb4
Security Audit — socket — python-sdk