architectural-constraints
Warn
Audited by Socket on Jul 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is defensive sandboxing, but the concrete execution example runs untrusted Python directly on the host and inherits host environment variables, undermining the core security claims. There is no clear exfiltration endpoint or malware payload, so this is better classified as a risky, internally inconsistent security skill rather than confirmed malicious content.
Confidence: 90%Severity: 74%
Audit Metadata