agentar
Warn
Audited by Socket on Jul 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose fits a CLI integration, but the actual footprint is disproportionate: it installs an unverifiable remote-script-based binary, then forwards API keys and user files to it, and also instructs transitive skill installation. The main risk is supply-chain and credential forwarding rather than confirmed malware.
Confidence: 88%Severity: 86%
Audit Metadata