self-improving-agent

Warn

Audited by Socket on Jul 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core behavior—curating memory into durable project rules—is coherent, but the install footprint is mixed. The OpenClaw/ClawHub path is plausibly same-ecosystem, while the alternative Codex install path relies on a personal-repo script and is not verified against official OpenAI docs. The skill also has transitive trust risk because it can create/install further skills and persists command-error output into memory, which could capture sensitive data. No confirmed malicious exfiltration or hidden behavior is present.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Jul 18, 2026, 04:20 PM
Package URL
pkg:socket/skills-sh/johnefemer%2Fskillfish%2Fself-improving-agent%2F@67f41c0e25834c3be123866ab90c45291c3b3edcf6ed30ff35aa1c4081ef399a
Security Audit — socket — self-improving-agent