autonomous-loops
Warn
Audited by Socket on Apr 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill is internally consistent as an autonomy/automation guide, but its footprint is high-risk because it encourages unattended code execution, PR creation, and auto-merge workflows. The external installer is same-repo and publicly verifiable, so this is not strong evidence of malware, but the mutable curl|bash install path plus autonomous real-world actions and prompt-injection exposure make the skill security-significant.
Confidence: 89%Severity: 78%
Audit Metadata