integrate-agentkit-host

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/tool_exec.py

The code is an authentication and API proxy CLI, not apparent malware. It performs expected network operations against a user-configured Scalekit environment, but it has a serious credential-handling weakness because it prints OAuth access and refresh tokens in plaintext. The proxy also permits broad user-selected remote requests and local file upload/download operations, so it should be treated as a privileged administrative tool and restricted from untrusted users or CI logs. No obfuscated or hidden malicious payload is evident in the supplied fragment. The apparent syntax errors should be corrected or verified as possible transcription truncation.

Confidence: 97%Severity: 68%
Audit Metadata
Analyzed At
Sep 19, 2026, 02:19 PM
Package URL
pkg:socket/skills-sh/scalekit-inc%2Fauthstack%2Fintegrate-agentkit-host%2F@16b13eddbb9d77955afa3c03567d535611f57c4399592fbdb28e7521d6b95941
Security Audit — socket — integrate-agentkit-host