agent-estate

Warn

Audited by Socket on Aug 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's behavior matches its stated purpose, but that purpose is itself high risk: a persistent stop-blocking autonomous loop with cross-session memory and repeated action capability. Main concerns are autonomy abuse, ledger-driven prompt injection persistence, and executing repo-owned hook scripts from a personal GitHub clone; there is no clear evidence of credential theft or overt malware.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Aug 25, 2026, 10:51 AM
Package URL
pkg:socket/skills-sh/majiayu000%2Fclaude-skill-registry%2Fagent-estate%2F@6691d9dfc9c984f7adde96575ac80bcbba2028d15b05a5e0b0e7233fb4b01a67
Security Audit — socket — agent-estate