cdo

Fail

Audited by Socket on Mar 21, 2026

2 alerts found:

AnomalyObfuscated File
AnomalyLOW
SKILL.md

SUSPICIOUS. The core orchestration capabilities fit the stated deliberation purpose, so this is not fundamentally incompatible or overtly malicious. Risk comes from broad agent/write/bash powers, automatic skill expansion, persistent logging, and especially `lev-exec` sending context to external model tooling, including third-party OpenRouter, which creates a real data-exposure and trust-boundary concern.

Confidence: 80%Severity: 61%
Obfuscated FileHIGH
dispatch/skill-injection.md

This protocol is a high-risk prompt-injection and local supply-chain pattern: it prescribes reading local skill files and pasting their full contents verbatim into agent briefs without validation or sandboxing. The fragment itself is not malware, but adopting this workflow without strong mitigations (integrity checks for skill files and the CLI, static scanning for dangerous instructions, capability restrictions on agents, review and provenance tracking, sandboxed execution) creates a significant risk that compromised or malicious skill files can cause agents to exfiltrate data, execute commands, or otherwise perform unauthorized actions. Recommend adding mandatory integrity verification (signatures/checksums), static content scanning, allowlists for permissible operations, explicit capability restrictions for agents, and human review steps before injection.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 21, 2026, 06:49 PM
Package URL
pkg:socket/skills-sh/lev-os%2Fagents%2Fcdo%2F@0ddceed3229d6dea0b92a85823c3ecd2a07a3fe2
Security Audit — socket — cdo