use-coding-agents
Warn
Audited by Socket on Sep 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s behavior is mostly aligned with its stated orchestration purpose, but it normalizes running multiple external coding agents headlessly with dangerous approval-bypass flags, allowing autonomous code edits and commits with limited oversight. I found no clear malware, no hidden exfiltration endpoint, and no confirmed malicious installer in the provided content, but the operational risk is high because the skill delegates broad authority to networked third-party CLIs.
Confidence: 86%Severity: 72%
Audit Metadata