wasm-agent

Warn

Audited by Socket on Jun 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose is plausible, but the skill overclaims safety. Its stated 'full sandbox isolation' conflicts with granting host `Bash` access, which can bypass the sandbox entirely. No direct malware or credential-harvesting behavior is shown in the skill text, but the external MCP server is trusted transitively and its concrete data flows are not disclosed.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 13, 2026, 01:22 PM
Package URL
pkg:socket/skills-sh/ruvnet%2Fclaude-flow%2Fwasm-agent%2F@7c942c18b75bd6e5c8c8dc37472fc5ef75ab1ce83270bb336a4344d23a040a5b
Security Audit — socket — wasm-agent