architecture-autopilot
Warn
Audited by Socket on May 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's purpose is coherent, but it materially expands agent autonomy by orchestrating repo analysis, issue publication, and code implementation through multiple delegated skills and sub-agents. The biggest risks are transitive skill installation (`setup-matt-pocock-skills`), broad delegated execution trust, and autonomous action after minimal user confirmation; there is no clear evidence of credential theft or malicious exfiltration in this artifact alone.
Confidence: 83%Severity: 72%
Audit Metadata