open-agent-sdk-typescript

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly aligned with its stated purpose as an agent SDK guide, and the main package install path is coherent. However, its footprint is high-risk for agent use: autonomous permission bypass, shell/file/git capabilities, npx-fetched MCP servers, and optional routing of API traffic through third-party OpenRouter. This looks more like a powerful but risky developer skill than malware.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
May 17, 2026, 11:59 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fai-agent-skills%2Fopen-agent-sdk-typescript%2F@47d168e7934ad5d9f9b0e10fba5919608fc9dd4a
Security Audit — socket — open-agent-sdk-typescript