agentar

Warn

Audited by Socket on Jul 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose fits a CLI integration, but the actual footprint is disproportionate: it installs an unverifiable remote-script-based binary, then forwards API keys and user files to it, and also instructs transitive skill installation. The main risk is supply-chain and credential forwarding rather than confirmed malware.

Confidence: 88%Severity: 86%
Audit Metadata
Analyzed At
Jul 14, 2026, 01:52 PM
Package URL
pkg:socket/skills-sh/OpenAgentar%2Fskills%2Fagentar%2F@c4ee8624f5dcb9ae4bd3b890a4b5c23e213c9d87556a3c5877c0a30d3b10a1ad
Security Audit — socket — agentar