autopilot

Warn

Audited by Socket on May 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s behavior is broadly aligned with an 'autopilot developer workflow,' but its trust footprint is high. The main concerns are extensive autonomous real-world actions without intermediate approval, transitive execution through other skills, and reliance on an unverifiable `af` CLI for Jira/Jenkins operations. No clear evidence of malware or credential theft was shown, but the overall security risk is high.

Confidence: 86%Severity: 81%
Audit Metadata
Analyzed At
May 10, 2026, 01:36 PM
Package URL
pkg:socket/skills-sh/avantmedialtd%2Fskills%2Fautopilot%2F@2533a9cf0c726c4adf3a7b6fe2999f743cda85bb