ucoz-provisioning-skill

Warn

Audited by Socket on Jun 29, 2026

3 alerts found:

Securityx2Anomaly
SecurityMEDIUM
templates/hermes-config.yaml
SecurityMEDIUM
templates/generic-mcp-env.sh
AnomalyLOW
browser-runner/provision-new-site.mjs

This file is a thin, high-impact loader that executes bundled sibling code synchronously during module load. It forwards stdio and the full environment, which can amplify the impact of whatever the companion script does. While the snippet itself shows no overt malicious behavior, its execution-on-import pattern is a notable supply-chain risk indicator; assessing true maliciousness requires inspecting the contents of ucoz-provision.cjs.

Confidence: 60%Severity: 65%
Audit Metadata
Analyzed At
Jun 29, 2026, 10:17 AM
Package URL
pkg:socket/skills-sh/ucoz-skills%2Fagent-skills%2Fucoz-provisioning-skill%2F@d5beaae16c125620b2b18b1d7468b44b8315b0b2dcc257c92ed420e72fc77f10
Security Audit — socket — ucoz-provisioning-skill