autonomous
Warn
Audited by Socket on Sep 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's purpose matches software-delivery automation, but it materially increases autonomous action scope by directing the agent to branch, open PRs, watch CI, auto-merge, and proceed without further confirmation. No confirmed credential theft or exfiltration is shown, and the flagged command injection appears documentary, but the combination of autonomous merge behavior, peer-agent orchestration, transitive skill use, and partially unverifiable custom tooling makes this a high workflow-risk skill rather than benign guidance.
Confidence: 87%Severity: 76%
Audit Metadata