autonomous-agent

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s core problem is not explicit malware but unsafe autonomy. Its stated purpose matches autonomous orchestration, yet it combines silent operation, web research over untrusted sources, and execution of externally derived fixes without provenance controls. That makes the skill high risk for unintended actions and indirect prompt-injection, even though no explicit credential theft or concrete malicious payload is shown.

Confidence: 92%Severity: 82%
Audit Metadata
Analyzed At
Aug 26, 2026, 11:19 AM
Package URL
pkg:socket/skills-sh/cyangzhou%2Ftrae-automation-workflows%2Fautonomous-agent%2F@18aa32e1014eeddd2a6921c9b5275cad29bd33915f2c19f33324d8b006ce6b79
Security Audit — socket — autonomous-agent