world2agent-protocol

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose matches sensor/plugin installation, but its footprint includes high-risk transitive skill installation and an explicit dangerous development-channel load. No clear credential theft or malicious exfiltration is shown, yet execution trust is weak and downstream third-party sensors/plugins materially raise security risk.

Confidence: 82%Severity: 76%
Audit Metadata
Analyzed At
May 17, 2026, 11:32 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fai-agent-skills%2Fworld2agent-protocol%2F@df2e93b3dd7e6d1b560dab0236cf6b301f39bae1
Security Audit — socket — world2agent-protocol