agent-incident

Warn

Audited by Socket on Jul 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose and data flows are broadly consistent with incident.io triage and response, and it points to official incident.io auth/API concepts rather than third-party interception. The main issue is install/execution trust: it relies on a local `agent-incident` CLI whose official provenance was not verified from the evidence, yet that CLI receives API credentials and can perform impactful operational actions. This is more consistent with a high-risk unverifiable dependency than confirmed malware.

Confidence: 83%Severity: 78%
Audit Metadata
Analyzed At
Jul 7, 2026, 01:37 PM
Package URL
pkg:socket/skills-sh/shhac%2Fagent-skills%2Fagent-incident%2F@08211ea63a41b6fa7789cb5c1aafe77d88d5eaacc46f067c3dcf999f0d3509dd
Security Audit — socket — agent-incident