task-commander

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose matches orchestration, but its footprint is high-risk: it enables autonomous delegation, repo-modifying git actions, peer-to-peer prompt/data transfer, and long-running workflows with limited per-action approval. There is no obvious credential harvesting or exfiltration endpoint in the text, so this is not confirmed malware, but the autonomy and transitive trust surface make it a significant security risk for an AI agent.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Apr 1, 2026, 05:36 AM
Package URL
pkg:socket/skills-sh/KevinZai%2Fcc-commander%2Ftask-commander%2F@8d52fca6a849879dbdba4162d6fa3b2d6f43ed5e
Security Audit — socket — task-commander