shell-integration

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align as a shell-integration reference, and most scanner hits are documentation artifacts. However, its install/distribution guidance includes downloading and executing an unverifiable placeholder binary, then eval/source of shell code emitted by that binary, which creates a disproportionate supply-chain risk for a documentation skill even without evidence of active malware or exfiltration.

Confidence: 90%Severity: 72%
AnomalyLOW
references/plugin-distribution.md

No direct malicious behavior is evident in the supplied fragment. It describes conventional shell-plugin integration, but it carries a meaningful supply-chain and shell-code execution risk: an unverified binary from a mutable latest-release URL is executed, and its output is repeatedly evaluated or sourced. Pin releases, verify signatures or checksums, minimize eval usage, and protect cached/configuration files before using this pattern in production.

Confidence: 98%Severity: 68%
Audit Metadata
Analyzed At
Sep 15, 2026, 11:52 AM
Package URL
pkg:socket/skills-sh/oakoss%2Fagent-skills%2Fshell-integration%2F@2091163f0f81e01a0a560cd9a2acb135f57dad2bf9d71003278d77485ef069ec
Security Audit — socket — shell-integration