self-improving-agent
Warn
Audited by Socket on Aug 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s self-modifying behavior broadly matches its purpose, but the install path is an unpinned external npx command with transitive registry trust, and the design lets untrusted feedback influence persistent prompt/skill changes. No clear credential theft or malicious exfiltration is shown, but the autonomy and supply-chain footprint are higher than a normal documentation-only skill.
Confidence: 84%Severity: 63%
Audit Metadata