personal-loop

Warn

Audited by Socket on Jun 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent with its stated purpose, but it grants an AI agent broad autonomous authority to modify code and run local gate commands based on external prompt files, without human approval. There is no clear malware behavior, credential harvesting, third-party proxying, or supply-chain abuse in the skill itself, but its autonomy and prompt-driven execution make it a medium-risk workflow skill.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 17, 2026, 06:52 PM
Package URL
pkg:socket/skills-sh/envoydev%2Fskills%2Fpersonal-loop%2F@8ca724323c3654796b5d83a0be273839554943fc36fa6f25e4236893b37ab22f
Security Audit — socket — personal-loop