agent-skillguard

Fail

Audited by Socket on Sep 9, 2026

3 alerts found:

SecurityAnomalyMalware
SecurityMEDIUM
fixtures/positive/sg001.md

No code was supplied. The included command is an unsafe remote-command execution pattern and should not be executed without independently reviewing and verifying the script.

Confidence: 99%Severity: 72%
AnomalyLOW
fixtures/positive/sg006.ps1

The code creates logon-based scheduled-task persistence and automatically executes example.exe. This is a security-relevant behavior with dual legitimate and malicious use; the fragment alone does not establish malware, but it should be authorized and the executable path verified.

Confidence: 99%Severity: 65%
MalwareHIGH
fixtures/positive/sg002.sh

The code is an extremely dangerous destructive command. It attempts to recursively and forcibly remove the entire root filesystem and should not be executed.

Confidence: 100%Severity: 100%
Audit Metadata
Analyzed At
Sep 9, 2026, 03:58 AM
Package URL
pkg:socket/skills-sh/practicalswan%2Fagent-skills%2Fagent-skillguard%2F@897fb402b1b498ca0962bae9d613fc71b1976b9cdc2c435e86dc1d7ee9f91031
Security Audit — socket — agent-skillguard