auto-improve

Warn

Audited by Socket on May 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's core purpose is coherent, but its footprint is high-risk because it grants an AI agent autonomous file mutation, persistent memory writes, hidden background saves, and external GitHub push/PR actions across broad local content. Data flows mostly match the stated purpose and do not show clear credential theft, so this is not confirmed malware, but the autonomy and scope are disproportionate enough to classify as high security risk.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
May 14, 2026, 03:13 PM
Package URL
pkg:socket/skills-sh/alvarovillalbaa%2Fplugins%2Fauto-improve%2F@1e8c308ba36909fd55534694f6994042c7507eb7
Security Audit — socket — auto-improve