agent-incident
Warn
Audited by Socket on Jul 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s purpose and data flows are broadly consistent with incident.io triage and response, and it points to official incident.io auth/API concepts rather than third-party interception. The main issue is install/execution trust: it relies on a local `agent-incident` CLI whose official provenance was not verified from the evidence, yet that CLI receives API credentials and can perform impactful operational actions. This is more consistent with a high-risk unverifiable dependency than confirmed malware.
Confidence: 83%Severity: 78%
Audit Metadata