skill-ecosystem-doctor
Warn
Audited by Socket on Aug 6, 2026
1 alert found:
AnomalyAnomalyscripts/ecosystem_reconcile.py
LOWAnomalyLOW
scripts/ecosystem_reconcile.py
No clear evidence of classic malware (no network, no subprocess execution, no eval/exec, no credential theft) is present in this fragment. However, it is a high-privilege local file/symlink mutator: with --apply it overwrites SKILL.md and registry JSON files and creates/removes symlinks based largely on an external policy file. If the policy (or plan_plugin_states implementation) is compromised, this tool could facilitate operational sabotage of the local codex/claude skill directories. Probability of intentional malicious behavior in this specific code is low, but security risk from misuse/poisoned inputs is moderate.
Confidence: 68%Severity: 52%
Audit Metadata