ov-kanban

Warn

Audited by Socket on Oct 2, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core kanban storage behavior is coherent with the stated purpose, but the optional loop materially expands scope: it runs an agent autonomously, bypasses approvals/sandbox by default, and executes a templated command through eval. No clear credential theft or off-purpose exfiltration is shown, so this is not confirmed malware, but it is a high-risk workflow skill due to autonomous execution and command-template injection surface.

Confidence: 91%Severity: 83%
SecurityMEDIUM
references/loop.sh

This is a task-loop wrapper rather than evident malware. However, its default command disables agent approval and sandbox protections, and eval makes the configurable command an arbitrary shell-execution point. Use only with trusted configuration and task sources, or remove eval and retain execution sandboxing.

Confidence: 98%Severity: 79%
Audit Metadata
Analyzed At
Oct 2, 2026, 09:48 PM
Package URL
pkg:socket/skills-sh/volcengine%2Fopenviking%2Fov-kanban%2F@b8665d04af5a9ecc0b9a97ce63fc0fe43fdc02f8af9c59f79331bd9a4c18e984
Security Audit — socket — ov-kanban