autonomous

Warn

Audited by Socket on Sep 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose matches software-delivery automation, but it materially increases autonomous action scope by directing the agent to branch, open PRs, watch CI, auto-merge, and proceed without further confirmation. No confirmed credential theft or exfiltration is shown, and the flagged command injection appears documentary, but the combination of autonomous merge behavior, peer-agent orchestration, transitive skill use, and partially unverifiable custom tooling makes this a high workflow-risk skill rather than benign guidance.

Confidence: 87%Severity: 76%
Audit Metadata
Analyzed At
Sep 7, 2026, 03:07 PM
Package URL
pkg:socket/skills-sh/broomva%2Fskills%2Fautonomous%2F@c76d8d1f90a7e3fff3b1d50f70ab8c75105ae96a4abbdde6e6d4b494ef603b4a
Security Audit — socket — autonomous