dual-ai

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's core purpose matches its capabilities, but it deliberately grants two external AI agents full-permission/approval-bypass access, forwards project context to them, and can chain into additional skills/workflows. Install trust is mostly acceptable for official Claude/Codex CLIs, but the autonomy, prompt-injection surface, and data exposure make the overall skill high risk.

Confidence: 87%Severity: 81%
Audit Metadata
Analyzed At
Aug 24, 2026, 08:23 PM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fdual-ai%2F@fb2edaf385fa3a888970b49eb6d90d791a24749c9c8fae71803168da16089f5c
Security Audit — socket — dual-ai