command-code
Warn
Audited by Socket on Jul 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is coherent with its stated purpose, and the installer path appears same-org and npm-based, but its actual footprint is high-risk because it centers on launching an external coding agent in fully unsupervised `--yolo` mode, can ingest untrusted GitHub issue content, and exposes a transitive skill-install path. This is better classified as a risky orchestration skill than malware.
Confidence: 90%Severity: 74%
Audit Metadata