auto-improve
Warn
Audited by Socket on May 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's core purpose is coherent, but its footprint is high-risk because it grants an AI agent autonomous file mutation, persistent memory writes, hidden background saves, and external GitHub push/PR actions across broad local content. Data flows mostly match the stated purpose and do not show clear credential theft, so this is not confirmed malware, but the autonomy and scope are disproportionate enough to classify as high security risk.
Confidence: 89%Severity: 84%
Audit Metadata