comet-open

Warn

Audited by Socket on May 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated workflow purpose is plausible, but the skill’s real footprint includes mandatory transitive skill loading, sourcing of a discovered local shell script, and autonomous progression to the next phase. The main risk is trust expansion and unreviewed code execution rather than confirmed malware or direct exfiltration.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
May 29, 2026, 11:24 AM
Package URL
pkg:socket/skills-sh/rpamis%2Fcomet%2Fcomet-open%2F@3f6978b0e59ebc9d1842e3469df271d3de4d6c5c
Security Audit — socket — comet-open