agent-tools

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Overall, the skill is purpose-aligned with orchestrating a broad AI app ecosystem via a centralized CLI. However, its installation pattern (curl | sh) and potential credential handling for external services introduce notable security considerations. The data flows involve uploading local files to cloud apps and posting to social platforms, which are expected for this tool but require explicit secure handling and clear user consent. Given the combination of remote installation, broad API access, and multi-service data flows, the risk profile is elevated; classify as SUSPICIOUS with a leaning toward BENIGN depending on implementation details (e.g., solid credential management, explicit user prompts, strict data handling policies).

Confidence: 65%Severity: 55%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:52 PM
Package URL
pkg:socket/skills-sh/inference-sh%2Fagent-skills-registry%2Fagent-tools%2F@07fff5cd7b40cd49a49c5d86527de42fae02b476
Security Audit — socket — agent-tools