dkod
Warn
Audited by Socket on Apr 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is broadly coherent with its stated purpose of parallel code editing via dkod, and the remote MCP install/auth pattern matches Anthropic’s documented workflow. However, it asks the agent to add a third-party MCP service/plugin, sends repository data to dkod-controlled endpoints, and can push PRs; combined with the unverified plugin publisher relationship, this makes it medium risk rather than benign.
Confidence: 81%Severity: 61%
Audit Metadata