task-commander
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose matches orchestration, but its footprint is high-risk: it enables autonomous delegation, repo-modifying git actions, peer-to-peer prompt/data transfer, and long-running workflows with limited per-action approval. There is no obvious credential harvesting or exfiltration endpoint in the text, so this is not confirmed malware, but the autonomy and transitive trust surface make it a significant security risk for an AI agent.
Confidence: 86%Severity: 72%
Audit Metadata