infinite-dev

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s capabilities broadly match its stated purpose, and the referenced Claude tooling appears official, but it enables high-authority unattended coding loops, parallel subagents, and operation with `--dangerously-skip-permissions`. This is not confirmed malware or credential harvesting, yet it is a high-risk autonomous agent skill because of the breadth of execution and file-modification authority.

Confidence: 87%Severity: 76%
Audit Metadata
Analyzed At
Mar 21, 2026, 01:02 PM
Package URL
pkg:socket/skills-sh/RobertWang4%2Finfinite-dev-skill%2Finfinite-dev%2F@824c9e7c9b95cb756939c2411c288c3bd17fe1e2