init

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s stated purpose is narrow and most actions fit that purpose, but its install instructions are internally inconsistent with the verified upstream distribution of Agent Validator. That supply-chain mismatch, plus undeclared delegation to another skill with skipped checks, raises medium security concern even though there is no clear credential theft, exfiltration, or malware behavior.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 03:49 AM
Package URL
pkg:socket/skills-sh/Codagent-AI%2Fagent-skills%2Finit%2F@35801560a2f1bef71bc2098248b40e3e3c82f5f1