coding-agent-loops
Warn
Audited by Socket on Jul 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose matches its capabilities, but it normalizes unattended coding-agent loops with `--dangerously-skip-permissions`, creating high real-world execution risk disproportionate to a generic workflow helper. No clear credential theft or malicious exfiltration is present, but the autonomous shell/file action model makes it a high-risk operational skill.
Confidence: 89%Severity: 76%
Audit Metadata