loop-coding

Warn

Audited by Socket on Aug 10, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose broadly matches large-scale coding orchestration, but its footprint is expansive. The main risks are third-party skill rental from skills.sh, transitive trust in downloaded skill content, autonomous push/staging actions, and outbound Telegram artifact delivery; these are proportionally risky even if some external tools are official.

Confidence: 88%Severity: 81%
AnomalyLOW
scripts/escalate.sh

This module is not indicative of hidden malware/backdoors; it is a straightforward escalation/notification script. However, it is a clear and high-impact data-sharing mechanism: it uploads local REVIEW.md/FIX-LOG.md contents to Telegram using a bot token read from disk, with chat destination driven by an environment variable. The main security concern is sensitive information exfiltration (privacy/IP/secrets) if the artifacts contain confidential data or if PRINCE_CHAT_ID/RUN_DIR are misconfigured or controlled unexpectedly.

Confidence: 72%Severity: 60%
Audit Metadata
Analyzed At
Aug 10, 2026, 08:03 PM
Package URL
pkg:socket/skills-sh/qwwiwi%2Fagentos-skills-public%2Floop-coding%2F@080518db8ef1ce595a7a8519062bffab3edc2a3b4780c6687418ffdca41c8b39
Security Audit — socket — loop-coding