aicoo
Audited by Socket on Jul 5, 2026
2 alerts found:
Anomalyx2SUSPICIOUS: the skill is mostly coherent with Aicoo’s stated platform purpose and uses first-party aicoo.io endpoints, so it is not strong evidence of malware. However, it enables broad remote data sync, transcript access, autonomous loops, outbound posting/messaging, and arbitrary MCP server configuration, making it a medium-to-high security/privacy risk even though the core integration appears legitimate.
This module is primarily a hook configuration that delegates behavior to two local shell scripts executed via relative paths on specific runtime events. The fragment itself provides no direct evidence of malware, but it establishes a sensitive arbitrary-command execution pathway contingent on the integrity of the referenced .sh files. Inspect and verify the provenance/integrity of both scripts and assess what they do with filesystem/network/process privileges.