colosseum-copilot
Warn
Audited by Socket on Aug 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. Core Copilot API usage is aligned with the stated purpose and uses official Colosseum endpoints, but the skill stores the PAT in plaintext and includes telemetry routed to a user-configured Convex URL, with a start event potentially sent before the telemetry prompt flow. This is not confirmed malware, but the telemetry/data-flow design and local secret handling create medium security risk.
Confidence: 91%Severity: 58%
Audit Metadata