openmonoagent-local-ai-coding-agent

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities mostly match a local coding-agent purpose, but the footprint is higher risk than the 'local-first' framing suggests. The main concerns are the mutable raw-GitHub installer, third-party runtime dependencies, remote inference/relay data flows, and an agent design that combines untrusted content processing with file-write and command execution. Not confirmed malware, but medium-high security risk for a skill.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
May 17, 2026, 07:30 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fai-agent-skills%2Fopenmonoagent-local-ai-coding-agent%2F@9eccf5223e3ae7da9a7123087b11ff827734fead
Security Audit — socket — openmonoagent-local-ai-coding-agent