yolo
Warn
Audited by Socket on Aug 30, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated QA purpose is plausible, but the footprint is too broad and autonomous for that role. The biggest issues are permissionless file deletion/editing including `.env` and dotfiles, plus consuming external review/web content while retaining write and execution powers. No clear evidence of malware or credential theft, but this is a high-impact agent skill that should be tightly constrained.
Confidence: 86%Severity: 74%
Audit Metadata