wsl-containers

Warn

Audited by Socket on Sep 3, 2026

1 alert found:

Security
SecurityMEDIUM
references/windows-skill-import.md

This fragment describes a remote-to-local import pipeline that enumerates and downloads repository files over HTTPS and writes them into a user-local Hermes skills import directory under `AppData/Local`. While the content type is described as `SKILL.md`, the workflow has supply-chain/content-injection characteristics and explicitly aims to bypass Windows Defender/policy restrictions. No code is provided, so path sanitization, integrity/authentication controls, and whether imported artifacts can execute or cause harm cannot be verified; nonetheless, the combination of untrusted remote content ingestion into an application import area and evasion-oriented framing warrants security review and stronger controls (allowlists, commit/hash pinning, signature verification, and strict path/content validation).

Confidence: 45%Severity: 70%
Audit Metadata
Analyzed At
Sep 3, 2026, 02:39 AM
Package URL
pkg:socket/skills-sh/timsonner%2Fagent-skills%2Fwsl-containers%2F@1fe47ddc8d82449b0b75cdd5ac986030c2f8841221d060817ce4ac43aeea56dc
Security Audit — socket — wsl-containers