agent-mode
Warn
Audited by Socket on Jul 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The stated purpose matches document automation in WPS, but the mode is high-risk because it auto-executes model-generated JavaScript and grants wildcard skill scope. There is no clear credential theft or third-party exfiltration path in the provided text, so this is not confirmed malware, but the autonomous execution footprint is broader than necessary for safe document editing.
Confidence: 89%Severity: 81%
Audit Metadata