python-executor

Warn

Audited by Socket on Jul 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core capability—remote Python execution via inference.sh—is aligned with its purpose, and the installer appears to belong to the same org/ecosystem rather than an unrelated third party. However, it expands the agent’s reach through arbitrary code execution, web scraping, remote file return, and transitive skill installation, with install instructions partly routed through mutable raw GitHub content and curl|sh. This looks like a legitimate but high-impact hosted executor skill, not confirmed malware.

Confidence: 82%Severity: 61%
Audit Metadata
Analyzed At
Jul 23, 2026, 06:06 PM
Package URL
pkg:socket/skills-sh/magentosh%2Fskills%2Fpython-executor%2F@81e4b2f65cdeb73772a9c06be4aef10b5c2c21d3bdc58b01541e0a5d047bfb87
Security Audit — socket — python-executor