agent-tools
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS rather than malicious. The core inference.sh CLI behavior is broadly consistent with the stated purpose and uses official same-project domains, so the main concern is install trust, not hidden exfiltration. Risk rises because the skill chains installation of other skills and enables broad remote actions, including local file uploads and Twitter/X automation with real-world consequences.
Confidence: 88%Severity: 64%
Audit Metadata