long-running-agent

Warn

Audited by Socket on May 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is purpose-aligned and shows no clear credential theft, hidden exfiltration, or dubious installer behavior, but it enables high-autonomy code execution, subagent spawning, repeated file writes, and repository merges with limited human oversight. The main risk is operational autonomy and prompt-injection exposure from untrusted project or research content, not confirmed malicious intent.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
May 7, 2026, 08:04 PM
Package URL
pkg:socket/skills-sh/jarrodwatts%2Flong-running-agent-skill%2Flong-running-agent%2F@57942f364bd4800f80d5031c4b98d49863e2a9dd