executing

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent for swarm task execution, but it grants an AI worker broad autonomous powers to edit code, commit changes, and communicate status through external coordination tooling. Main concerns are action autonomy and dependency trust—especially the external br/bv/Agent Mail toolchain and Agent Mail’s curl|bash installer—rather than clear malware or deceptive exfiltration.

Confidence: 83%Severity: 67%
Audit Metadata
Analyzed At
Apr 14, 2026, 02:28 PM
Package URL
pkg:socket/skills-sh/hoangnb24%2Fskills%2Fexecuting%2F@375257bca345b61826dfdab232b76ebde4a1c008