agent-builder

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Security
SecurityMEDIUM
tools.py

The code is an agent orchestration and workspace-management module, not clear malware. It performs substantial filesystem writes, scheduled-task registration, generated-script overwrites, and recursive deletion. The main security concern is path traversal because agent and team values are not consistently validated outside agent creation; this can expose task files or make deletion/modification operations escape the intended workspace. The malformed assignment and appended unrelated prompt content indicate source corruption and would likely prevent normal execution. Review and fix path validation, constrain all resolved paths beneath the workspace, and treat generated prompts/scripts as untrusted.

Confidence: 98%Severity: 78%
Audit Metadata
Analyzed At
Sep 17, 2026, 04:29 AM
Package URL
pkg:socket/skills-sh/starchild-ai-agent%2Fofficial-skills%2Fagent-builder%2F@fc7aa0aa465d4f195162730616e5e13ecfb45a08c2dacaaad4c30a1e9b549d59
Security Audit — socket — agent-builder