awesome-claude-code-subagents
Warn
Audited by Socket on May 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the repo and install paths appear to be legitimately associated with VoltAgent, so this is not confirmed malware. However, it is a transitive installer for 130+ remote subagents, uses unpinned raw GitHub downloads, includes direct script execution, and advertises offensive-security agents; that combination makes the skill medium-to-high risk despite coherent stated purpose.
Confidence: 87%Severity: 68%
Audit Metadata