cc-yolo-mode

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s main risk is not malware but disproportionate autonomy. It grants an AI agent web access, bash, editing, and iterative self-directed execution with minimal confirmation, plus cross-project persistence in ~/.claude/commander/. No clear credential theft or external exfiltration is present, but the capability mix is high-risk and not fully consistent with its own project-bound guardrails.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Apr 8, 2026, 02:31 PM
Package URL
pkg:socket/skills-sh/KevinZai%2Fcc-commander%2Fcc-yolo-mode%2F@84f36739f49d0fe93185428e160152c50833b42d
Security Audit — socket — cc-yolo-mode