agent-skillguard
Fail
Audited by Socket on Sep 9, 2026
3 alerts found:
SecurityAnomalyMalwareSecurityfixtures/positive/sg001.md
MEDIUMSecurityMEDIUM
fixtures/positive/sg001.md
No code was supplied. The included command is an unsafe remote-command execution pattern and should not be executed without independently reviewing and verifying the script.
Confidence: 99%Severity: 72%
Anomalyfixtures/positive/sg006.ps1
LOWAnomalyLOW
fixtures/positive/sg006.ps1
The code creates logon-based scheduled-task persistence and automatically executes example.exe. This is a security-relevant behavior with dual legitimate and malicious use; the fragment alone does not establish malware, but it should be authorized and the executable path verified.
Confidence: 99%Severity: 65%
Malwarefixtures/positive/sg002.sh
HIGHMalwareHIGH
fixtures/positive/sg002.sh
The code is an extremely dangerous destructive command. It attempts to recursively and forcibly remove the entire root filesystem and should not be executed.
Confidence: 100%Severity: 100%
Audit Metadata