sim-obliterator

Warn

Audited by Socket on Apr 7, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
CARD.yml

No direct malicious indicators are visible in this YAML configuration alone; it mainly describes a conversion/patch workflow. However, it creates a meaningful security risk by cloning and executing an external Git repository at runtime (unpinned/unverified in this fragment) and by executing setup/processing scripts with declared terminal-command capability plus broad filesystem read/write/patch effects on user-provided save files. This should be treated as a moderate supply-chain and execution-risk integration requiring review/pinning/signing of the sister repo and auditing of scripts/setup.py, inspect.py, uplift.py, and download.py for command/path safety and any unexpected network or data-access behavior.

Confidence: 56%Severity: 66%
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose and local file access are coherent for a Sims save-file bridge, and no clear exfiltration or credential harvesting appears in the text. The main concern is install/execution trust: the skill depends on an unreviewed sister repository and local setup script whose provenance and contents are not provided, so the overall risk is moderate even without evidence of confirmed malicious behavior.

Confidence: 79%Severity: 72%
Audit Metadata
Analyzed At
Apr 7, 2026, 07:40 PM
Package URL
pkg:socket/skills-sh/simhacker%2Fmoollm%2Fsim-obliterator%2F@342e04f924d3f08359376bcb975d9cae63e9baf1
Security Audit — socket — sim-obliterator