coding-agent
Warn
Audited by Socket on Aug 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose matches its capabilities as an orchestration guide, but it grants high-impact autonomous workflows: background agents, --yolo execution, PR review of untrusted content, and push/comment actions. Main concerns are autonomy abuse, prompt-injection exposure from external repos/PRs, and broad trust in third-party coding-agent CLIs rather than direct malware behavior.
Confidence: 84%Severity: 74%
Audit Metadata