supply-chain-protection

Fail

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONMETADATA_POISONINGPERSISTENCECOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill performs a global installation of the 'sfw' package ('npm i -g sfw'). The description identifies this as 'Socket Firewall', but the publicly available 'sfw' package on npm is a 'Simple File Watcher' tool. Installing and executing an unrelated package under a misleading name is a significant security risk.
  • [METADATA_POISONING]: The skill's name, description, and internal instructions consistently misidentify the 'sfw' package. This deception could lead users to trust the tool based on the reputation of 'Socket Firewall' while actually installing a different package.
  • [PERSISTENCE]: The skill writes persistent instructions to 'CLAUDE.md' requiring all future dependency commands to be prefixed with 'sfw'. This ensures that even after the initial setup, the agent remains constrained to use the potentially incorrect or malicious tool for all project maintenance.
  • [COMMAND_EXECUTION]: The skill executes 'sfw' commands with arguments derived from the detected package manager (e.g., 'sfw npm add is-odd'). If the installed 'sfw' package is not the intended firewall tool, these commands may have unpredictable effects on the system or project.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 17, 2026, 02:21 PM
Security Audit — agent-trust-hub — supply-chain-protection