openmonoagent-local-ai-coding-agent
Warn
Audited by Socket on May 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s capabilities mostly match a local coding-agent purpose, but the footprint is higher risk than the 'local-first' framing suggests. The main concerns are the mutable raw-GitHub installer, third-party runtime dependencies, remote inference/relay data flows, and an agent design that combines untrusted content processing with file-write and command execution. Not confirmed malware, but medium-high security risk for a skill.
Confidence: 84%Severity: 68%
Audit Metadata