acpx

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose matches agent orchestration, but its footprint is high-risk because it delegates to multiple external agent CLIs, allows arbitrary raw agent commands, and supports permissive autonomous execution modes like --approve-all. This looks more like a powerful automation/orchestration layer than a narrow helper, so the main concern is elevated execution and transitive trust rather than confirmed malware.

Confidence: 81%Severity: 62%
Audit Metadata
Analyzed At
Mar 31, 2026, 04:14 PM
Package URL
pkg:socket/skills-sh/asm3r96%2Fwave-driven-dev%2Facpx%2F@c7f86cb9f70f505d625a50b87dd757466a954fd4