openai-symphony-autonomous-agents
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill is internally coherent and uses an official OpenAI repo, so it does not look malicious. The main risk is intentional: it enables autonomous code changes and PR actions using powerful API tokens, with some added supply-chain exposure from following external setup steps and project tooling. Overall this is aligned but high-impact automation, not credential theft or covert exfiltration.
Confidence: 86%Severity: 74%
Audit Metadata