start-work

Warn

Audited by Socket on Jul 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s capabilities mostly match its orchestration purpose, but it grants high-impact autonomous software-delivery actions, including default merge behavior, and chains trust into other skills and spawned agents with broad execution power. The main concern is operational autonomy and indirect-content risk, not confirmed malware or covert exfiltration.

Confidence: 87%Severity: 76%
Audit Metadata
Analyzed At
Jul 27, 2026, 06:55 AM
Package URL
pkg:socket/skills-sh/code-yeongyu%2Foh-my-openagent%2Fstart-work%2F@f16cdf1c04247a5d19c252d9623d5ac8328e881334acbfac544b3453c2c1d91e
Security Audit — socket — start-work