aicoo
Audited by Socket on Aug 23, 2026
7 alerts found:
Securityx3Anomalyx4SUSPICIOUS: the skill is broadly consistent with Aicoo’s stated platform purpose and mostly uses same-org endpoints, so it does not look like confirmed malware. However, it enables extensive outbound sync of local context, optional transcript capture, third-party MCP integration, and autonomous messaging/posting loops, making its scope and real-world action surface high enough to be risky.
Overall benign in data flow and service alignment: it uses Aicoo's official endpoints for a matching social-board purpose. The main risk is scope of autonomous public actions via heartbeat, which can let the agent post, like, and comment without explicit approval each time.
SUSPICIOUS. The skill's capabilities mostly match its stated purpose and its network destinations are first-party Aicoo endpoints, not obvious credential-harvesting relays. However, it asks the agent to execute an unpinned npm package at runtime, forward authentication into that CLI, and enable automatic whole-session exfiltration to a remote service; with only partial publisher-verification evidence, this is a medium-risk supply-chain and privacy-sensitive skill rather than clearly benign.
SUSPICIOUS: the capability mostly matches the stated purpose of building Aicoo memory, and data flows go to the official Aicoo domain, but the skill performs broad local-context ingestion and forwards it remotely using a token sourced from an executed helper script whose public documentation/provenance is not fully consistent. Main risk is supply-chain and credential-forwarding trust, not confirmed malicious behavior.
SUSPICIOUS: the skill is broadly aligned with its collaboration purpose, but it expands the machine's exposure by installing and running a long-lived bridge from a mutable GitHub repo, forwarding an API token into that code, and opening a path for remote prompts to reach a local agent. Same-org source availability lowers concern versus malware, but the install and runtime trust model remain medium risk.
No clear malicious code indicators (backdoor/persistence/obfuscation/reverse shell) are present in this Bash fragment. However, the script intentionally uploads full contents of recently modified local Markdown files (and a raw git log summary) to a remote API using a Bearer token obtained by executing a local helper script. The most important risks are (1) potential privacy/data exfiltration depending on what the local Markdown contains and the scope/authorization of the destination service, and (2) supply-chain trust in `aicoo-auth.sh`, since its implementation is not shown and could introduce additional behavior beyond token retrieval.
No explicit malware or obfuscated payloads are present in this fragment, but it establishes automatic local shell script execution via 'type: command' hooks tied to sensitive events (including user prompt submission) and an additional conditional hook on write/edit operations. Because the referenced .sh files are not provided, the true behavior cannot be verified; this pattern is a significant supply-chain risk and warrants direct inspection and integrity validation of the invoked scripts (and their dependencies).