hosted-agents
Audited by Socket on Sep 14, 2026
2 alerts found:
Anomalyx2SUSPICIOUS. The skill's capabilities mostly align with its stated purpose, and external services/endpoints are official and coherent. Risk comes from enabling autonomous hosted execution, self-spawning sessions, shell-command examples with interpolated values, and user-token-based PR creation; the scanner's concealment claim is not substantiated by the visible content.
The code is largely a framework with many critical methods stubbed out, so no definitive malware behavior is observable in this fragment. However, it strongly indicates automated cloning and npm building/testing of potentially untrusted repositories and runs background dev processes. It also embeds GitHub tokens in the git clone URL (credential leakage risk) and constructs git config commands using user-controlled strings (possible command injection depending on execute_command escaping). Given the high-risk command-execution/supply-chain surface, this package warrants careful review of the missing implementations (sandboxing, escaping, network egress controls, dependency pinning/signature verification, and credential handling).