dual-ai
Warn
Audited by Socket on Aug 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s core behavior is coherent with its stated purpose, and the external CLIs appear official, but the purpose itself is high-risk: it spawns two new AI agents in parallel with dangerous permission-bypass flags and optional workflow chaining. This is not confirmed malware or credential theft, but it materially increases the chance of uncontrolled file changes, command execution, and unintended downstream actions.
Confidence: 90%Severity: 82%
Audit Metadata