agent-reach

Fail

Audited by Socket on May 29, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill's purpose is plausible, but its footprint is broad: mutable GitHub installation, auto-install of multiple external tools, and collection/forwarding of cookies, tokens, and proxy credentials. I do not see confirmed malware or explicit attacker-controlled exfiltration, but the install trust and credential-handling model are high risk and not well-scoped.

Confidence: 84%Severity: 83%
Audit Metadata
Analyzed At
May 29, 2026, 04:28 PM
Package URL
pkg:socket/skills-sh/GPTtang%2Fskill-atlas%2Fagent-reach%2F@29bf897c6786b3a14d7941f216ec54cff77f51f9
Security Audit — socket — agent-reach