use-coding-agents

Warn

Audited by Socket on Sep 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s behavior is mostly aligned with its stated orchestration purpose, but it normalizes running multiple external coding agents headlessly with dangerous approval-bypass flags, allowing autonomous code edits and commits with limited oversight. I found no clear malware, no hidden exfiltration endpoint, and no confirmed malicious installer in the provided content, but the operational risk is high because the skill delegates broad authority to networked third-party CLIs.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Sep 6, 2026, 09:17 PM
Package URL
pkg:socket/skills-sh/av%2Fskills%2Fuse-coding-agents%2F@65d05ede71d579c9a3b25cea5e9ad13039b4d132b4b18515486505a19dfddb82
Security Audit — socket — use-coding-agents