openai-symphony-autonomous-agents

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is internally coherent and uses an official OpenAI repo, so it does not look malicious. The main risk is intentional: it enables autonomous code changes and PR actions using powerful API tokens, with some added supply-chain exposure from following external setup steps and project tooling. Overall this is aligned but high-impact automation, not credential theft or covert exfiltration.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Sep 12, 2026, 08:37 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Ftrending-skills%2Fopenai-symphony-autonomous-agents%2F@81f536c290002ac329beed87b5168f4299563b3304c525f640b452151e9f0622
Security Audit — socket — openai-symphony-autonomous-agents