phantom-ai-coworker

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s broad capabilities generally match its stated purpose as an autonomous AI co-worker, so this is not obviously deceptive malware. However, its real footprint is extremely powerful: many credentials, host-level Docker control, shell execution, public endpoints, dynamic MCP tool creation, and autonomous outbound communications. The main concern is high operational/security risk and transitive trust expansion, not a hidden installer or clear credential-harvesting endpoint.

Confidence: 91%Severity: 88%
Audit Metadata
Analyzed At
Sep 12, 2026, 11:46 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Ftrending-skills%2Fphantom-ai-coworker%2F@6ef2cd37c1ef8597528fa3ef7f99b1b7b9a97fbe23cfd420718b588e912b10c7
Security Audit — socket — phantom-ai-coworker