architectural-constraints

Warn

Audited by Socket on Jul 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is defensive sandboxing, but the concrete execution example runs untrusted Python directly on the host and inherits host environment variables, undermining the core security claims. There is no clear exfiltration endpoint or malware payload, so this is better classified as a risky, internally inconsistent security skill rather than confirmed malicious content.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Jul 8, 2026, 12:22 PM
Package URL
pkg:socket/skills-sh/j4flmao%2Fagent-skills%2Farchitectural-constraints%2F@b616ac2c8a5c54fb37ee06ed3ca294739cba9e79a22345deeef79ad71f8d6e30
Security Audit — socket — architectural-constraints