colosseum-copilot

Warn

Audited by Socket on Aug 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. Core Copilot API usage is aligned with the stated purpose and uses official Colosseum endpoints, but the skill stores the PAT in plaintext and includes telemetry routed to a user-configured Convex URL, with a start event potentially sent before the telemetry prompt flow. This is not confirmed malware, but the telemetry/data-flow design and local secret handling create medium security risk.

Confidence: 91%Severity: 58%
Audit Metadata
Analyzed At
Aug 1, 2026, 11:05 AM
Package URL
pkg:socket/skills-sh/Sarthib7%2Fagentsmith%2Fcolosseum-copilot%2F@630730bc024ea99aa71aae72aa4950a27b2ccd83135079eebc10aadfff426cd3
Security Audit — socket — colosseum-copilot