capability-evolver

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s self-evolution purpose matches its capabilities, but its footprint is high risk: it ingests broad prior agent content, can autonomously write/apply changes, and supports unattended continuous operation. The main issue is not obvious malware but disproportionate autonomy and prompt-injection risk from letting an agent rewrite itself based on untrusted history.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
Mar 17, 2026, 07:19 PM
Package URL
pkg:socket/skills-sh/LJT-520%2FopenClaw-backup%2Fcapability-evolver%2F@655f5f42d774a2aa160e8954263a5170c1dc872c