yolo

Warn

Audited by Socket on Aug 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated QA purpose is plausible, but the footprint is too broad and autonomous for that role. The biggest issues are permissionless file deletion/editing including `.env` and dotfiles, plus consuming external review/web content while retaining write and execution powers. No clear evidence of malware or credential theft, but this is a high-impact agent skill that should be tightly constrained.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Aug 30, 2026, 10:31 PM
Package URL
pkg:socket/skills-sh/blockmatic%2Fbasilic-skills%2Fyolo%2F@5b0b2f7247664fa12f4c39e305b6a080d8ab3487d2dbae6d12a187e001acaa16
Security Audit — socket — yolo