zeroboot-vm-sandbox
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose, API endpoint, and data flow are broadly coherent for a remote code-sandbox service, and there is no clear malware behavior. However, the Python SDK install path is materially inconsistent with the project evidence: `pip install zeroboot` currently resolves to an unrelated placeholder package on PyPI, creating a real supply-chain trust problem. The skill should not be treated as benign until the package provenance is corrected or clearly verified.
Confidence: 91%Severity: 74%
Audit Metadata