soia-dev-skill-release

Warn

Audited by Socket on Jul 20, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/release_skills.py

This module is an orchestration/installer-like tool that does not show overt malicious logic, obfuscation, or data theft within the fragment. However, it substantially increases security risk by (1) executing an external Node CLI via npx using user-influenced repository/skill/agent parameters (runtime supply-chain/code execution boundary), (2) executing a local Python sync script from an installed directory that can be affected by upstream content, and (3) performing filesystem deletions and symlink creation based on skill names that are not explicitly validated for path-safety. Use only with strong trust/allowlisting and controlled provenance for the invoked npx tool, repository sources, and the installed sync script contents.

Confidence: 66%Severity: 60%
Audit Metadata
Analyzed At
Jul 20, 2026, 11:52 PM
Package URL
pkg:socket/skills-sh/soia-team%2Fsoia-open-skills%2Fsoia-dev-skill-release%2F@d6ae0f8046885686fa45fa085be80ad7282ad01ed4c71da4b0a2c76d0f35cfce
Security Audit — socket — soia-dev-skill-release