codeagent

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's capabilities mostly match its stated coding-orchestration purpose, but it meaningfully expands execution trust. Main concerns are the nonstandard GitHub/private install path, automatic trust in injected local skills, and documented sandbox/permission bypass behavior that can let an AI coding agent act with fewer guardrails.

Confidence: 83%Severity: 67%
Audit Metadata
Analyzed At
May 10, 2026, 04:18 AM
Package URL
pkg:socket/skills-sh/cexll%2Fmyclaude%2Fcodeagent%2F@e912d4f799132f1077a15f3504420b3596cba1de