autonomous

Warn

Audited by Socket on Aug 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s main issue is not classic malware behavior but broad autonomous authority: it enables an agent to edit code, open PRs, resolve comments, auto-merge, and possibly deploy with minimal human checkpoints. External prompt references appear same-org and consistent, so supply-chain concern is secondary; the core risk is high-impact autonomous workflow execution combined with untrusted external inputs.

Confidence: 88%Severity: 81%
Audit Metadata
Analyzed At
Aug 8, 2026, 03:34 PM
Package URL
pkg:socket/skills-sh/broomva%2Fskills%2Fautonomous%2F@f44e2ec5d454ddabfb66f429304d068dd07758f07c4d79aa45617e5417f22618
Security Audit — socket — autonomous