autopilot

Warn

Audited by Socket on Sep 3, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as an automation/orchestration tool, but it grants an AI agent broad autonomous execution by spawning headless provider CLIs with approval and sandbox bypass flags. There is no clear credential-harvesting or exfiltration behavior in the snippet, but the autonomy level, repository mutation, and transitive dependence on other skills make it high security risk.

Confidence: 88%Severity: 76%
SecurityMEDIUM
scripts/lib/provider.sh

No strong indicator of embedded malware is present in this fragment (no obvious backdoors, credential theft, or exfiltration code). The dominant concern is high operational risk: the runner executes provider CLIs with explicit safety/sandbox/approval-bypassing flags and selects the executed binary via environment variables. If an attacker can influence runtime environment or config, this design could enable significant compromise. Additional risk could come from unshown helper functions (path safety and sanitize_message effectiveness).

Confidence: 64%Severity: 70%
Audit Metadata
Analyzed At
Sep 3, 2026, 03:18 PM
Package URL
pkg:socket/skills-sh/leek%2Fagent-skills%2Fautopilot%2F@16df820b899fbb08da13fcb31dcb2dd27f8f9590875d096a432ad59b5f840577
Security Audit — socket — autopilot