cekura-self-improving-agent

Warn

Audited by Socket on May 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is largely purpose-aligned and routes data to official Cekura/Vapi services, but it has a broad operational footprint: autonomous live-agent edits, workspace file modification, and shell redeploy execution. The main security concern is high-impact automation plus a documented third-party MCP helper (`mcp-remote`) in some install paths, not obvious credential theft or covert exfiltration.

Confidence: 89%Severity: 63%
Audit Metadata
Analyzed At
May 14, 2026, 04:17 PM
Package URL
pkg:socket/skills-sh/cekura-ai%2Fcekura-skills%2Fcekura-self-improving-agent%2F@0915b3fd6361d385daeb1ab0f80a668b52acf0af