security-audit

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is largely coherent with its stated purpose and uses official GitHub workflows, so it does not look malicious. However, it grants an AI agent high-impact security-review capabilities, can mutate code and GitHub state, and chains into unseen sub-skills, making it medium-risk despite reasonable purpose alignment and approval checkpoints.

Confidence: 84%Severity: 59%
Audit Metadata
Analyzed At
Mar 20, 2026, 09:15 PM
Package URL
pkg:socket/skills-sh/andrewvaughan%2Fagent-council%2Fsecurity-audit%2F@a6658efe860cd9423ef8403cfd5579c2b99a6b29