eo-flow
Warn
Audited by Socket on May 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s behavior mostly matches its stated purpose as a tmux-based handoff/orchestration helper, and it does not contain obvious credential theft or exfiltration logic. However, it instructs launching Codex with approvals and sandbox bypassed, relies on a less-verifiable third-party tmux-bridge tool for control/message passing, and enables semi-autonomous execution flow across panes. That footprint is broader and riskier than a simple workflow helper, so the overall classification is suspicious rather than benign.
Confidence: 100%Severity: 60%
Audit Metadata