coding-agent

Warn

Audited by Socket on Aug 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose matches its capabilities as an orchestration guide, but it grants high-impact autonomous workflows: background agents, --yolo execution, PR review of untrusted content, and push/comment actions. Main concerns are autonomy abuse, prompt-injection exposure from external repos/PRs, and broad trust in third-party coding-agent CLIs rather than direct malware behavior.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Aug 1, 2026, 08:33 AM
Package URL
pkg:socket/skills-sh/LinkupPlatform%2Fopenclaw%2Fcoding-agent%2F@344742ad95e44233da86db34f87b3681c8d5db098b91a6c8f5412193a70426c4
Security Audit — socket — coding-agent