coding-agent

Warn

Audited by Socket on May 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's core purpose is coherent, but it grants broad orchestration power to external coding-agent CLIs and encourages high-autonomy repo actions like yolo execution, push, and PR creation/commenting. Main risks are autonomy abuse and prompt-injection through untrusted repo/PR content rather than overt malware or credential theft.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
May 16, 2026, 02:39 AM
Package URL
pkg:socket/skills-sh/elizaOS%2Feliza%2Fcoding-agent%2F@9ffd934988ac467bb3f1e218771e425977985a45
Security Audit — socket — coding-agent