ucoz-provisioning-skill
Warn
Audited by Socket on Jun 29, 2026
3 alerts found:
Securityx2AnomalySecuritytemplates/hermes-config.yaml
MEDIUMSecurityMEDIUM
templates/hermes-config.yaml
Securitytemplates/generic-mcp-env.sh
MEDIUMSecurityMEDIUM
templates/generic-mcp-env.sh
Anomalybrowser-runner/provision-new-site.mjs
LOWAnomalyLOW
browser-runner/provision-new-site.mjs
This file is a thin, high-impact loader that executes bundled sibling code synchronously during module load. It forwards stdio and the full environment, which can amplify the impact of whatever the companion script does. While the snippet itself shows no overt malicious behavior, its execution-on-import pattern is a notable supply-chain risk indicator; assessing true maliciousness requires inspecting the contents of ucoz-provision.cjs.
Confidence: 60%Severity: 65%
Audit Metadata