context-engineering-collection
Audited by Socket on Oct 1, 2026
4 alerts found:
Anomalyx3SecurityThe code is largely a framework with many critical methods stubbed out, so no definitive malware behavior is observable in this fragment. However, it strongly indicates automated cloning and npm building/testing of potentially untrusted repositories and runs background dev processes. It also embeds GitHub tokens in the git clone URL (credential leakage risk) and constructs git config commands using user-controlled strings (possible command injection depending on execute_command escaping). Given the high-risk command-execution/supply-chain surface, this package warrants careful review of the missing implementations (sandboxing, escaping, network egress controls, dependency pinning/signature verification, and credential handling).
SUSPICIOUS. The skill's capabilities mostly align with its stated purpose, and external services/endpoints are official and coherent. Risk comes from enabling autonomous hosted execution, self-spawning sessions, shell-command examples with interpolated values, and user-token-based PR creation; the scanner's concealment claim is not substantiated by the visible content.
SUSPICIOUS: the skill’s stated purpose is coherent, and its MiniMax references fit the debugging use case, but its core `rto` executable/package is not verifiably sourced. The main risk is supply-chain/install trust, plus sensitive-session analysis via hooks; I found no confirmed exfiltration, malicious pre-execution, or deceptive third-party credential routing in the provided text.
This module is a clipboard-based delivery mechanism for a hardcoded Git-based “install” shell command that includes fetching remote code and performing filesystem modifications (including rm -rf and cp into .cursor/skills). While the code does not execute the command or exfiltrate data, it meaningfully increases supply-chain and social-engineering risk by making a ready-to-run remote-install instruction easy to place into the user’s clipboard. The clipboard export (window.copySiteText) further broadens the impact within the page context.