dual-ai

Warn

Audited by Socket on Aug 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s core behavior is coherent with its stated purpose, and the external CLIs appear official, but the purpose itself is high-risk: it spawns two new AI agents in parallel with dangerous permission-bypass flags and optional workflow chaining. This is not confirmed malware or credential theft, but it materially increases the chance of uncontrolled file changes, command execution, and unintended downstream actions.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Aug 13, 2026, 03:13 PM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fdual-ai%2F@e8be7200dada592d7741c5a861c8fbdb1ab5a0aa5e518106afb97280233fc1f3
Security Audit — socket — dual-ai