capability-evolver
Warn
Audited by Socket on May 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s core behavior is mostly aligned with its stated self-evolution purpose and uses plausible official sources, but its footprint is high-impact: autonomous code rewriting plus indirect external data flow through a local Proxy. The localhost-only claim understates that workspace/runtime data can still reach EvoMap Hub via the Proxy, so the design is coherent but carries meaningful security risk and should be treated cautiously.
Confidence: 83%Severity: 64%
Audit Metadata