driving-claude-code-sessions
Warn
Audited by Socket on Sep 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s capabilities mostly match its project-manager purpose, but it grants broad autonomous control over other coding agents running with prompt bypass, stages multiple harness credentials, and exposes detailed event/transcript data. No clear malicious exfiltration or deceptive installer is present, yet the scope and autonomy are high enough to warrant caution.
Confidence: 90%Severity: 74%
Audit Metadata