evolution
Warn
Audited by Socket on May 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's self-improvement purpose broadly matches its local editing and routing behavior, but it achieves this through persistent auto-executing hooks and a pipe-to-shell installer on an unpinned branch. I found no strong evidence of credential theft or external exfiltration, so this is not confirmed malware; the main concern is broad autonomous/persistent execution scope that can modify repositories without tight user review.
Confidence: 87%Severity: 62%
Audit Metadata