anthropic-docs

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
references/agents-and-tools/tool-use/bash-tool.md

The code provides a clear implementation and documentation for a persistent bash execution tool. It contains no explicit malicious content, obfuscation, or hardcoded secrets. However, the tool permits arbitrary shell command execution from agent inputs and the provided validation examples are insufficient; this creates a significant supply-chain and host risk if deployed without strong sandboxing, allowlists, resource limits, and comprehensive validation/monitoring. Treat this component as high-risk capability rather than malware — safe only when run in tightly controlled isolated environments.

Confidence: 85%Severity: 65%
Audit Metadata
Analyzed At
Mar 24, 2026, 10:58 AM
Package URL
pkg:socket/skills-sh/wenerme%2Fai%2Fanthropic-docs%2F@b6a2bf86485f91cb1a0223d6bcd04a2d1d457d45
Security Audit — socket — anthropic-docs