agent-swarm

Warn

Audited by Socket on May 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities broadly match its stated orchestration purpose, but it materially expands execution scope by combining Bash, arbitrary job-defined shell commands, ambient credential use, and external AI CLI calls. The main concerns are command-execution flexibility, remote processing of repository content, and prompt-injection exposure during automated parallel workflows rather than clear malicious intent.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 24, 2026, 08:29 AM
Package URL
pkg:socket/skills-sh/richfrem%2FProject_Sanctuary%2Fagent-swarm%2F@e61988161bb37e286462e769721bb2b66c728135
Security Audit — socket — agent-swarm