aicoo

Warn

Audited by Socket on Jun 4, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill appears to target the official Aicoo service and its data flows are mostly coherent with that purpose, so there is no strong evidence of malware or credential theft. However, it has a broad operational footprint and enables autonomous messaging, posting, transcript access, and recurring actions with meaningful privacy and real-world action risk.

Confidence: 87%Severity: 68%
AnomalyLOW
hooks/claude-code/settings-example.json

This module is primarily a hook configuration that delegates behavior to two local shell scripts executed via relative paths on specific runtime events. The fragment itself provides no direct evidence of malware, but it establishes a sensitive arbitrary-command execution pathway contingent on the integrity of the referenced .sh files. Inspect and verify the provenance/integrity of both scripts and assess what they do with filesystem/network/process privileges.

Confidence: 55%Severity: 60%
Audit Metadata
Analyzed At
Jun 4, 2026, 12:20 PM
Package URL
pkg:socket/skills-sh/Aicoo-Team%2FAICOO-Skills%2Faicoo%2F@22b039cdf9381a1e8ac08ed8c8278c4e7f96c023
Security Audit — socket — aicoo