panel
Warn
Audited by Socket on Aug 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose matches multi-CLI orchestration, but the skill grants four external agent CLIs broad autonomous execution rights and sends them user prompts plus repository content. The main risk is not deception about purpose; it is disproportionate execution authority, external data exposure, and prompt-injection potential from running dangerous headless agents against local code.
Confidence: 90%Severity: 84%
Audit Metadata