coding-agent

Fail

Audited by Socket on Mar 29, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but it materially expands agent autonomy and external action scope. The biggest risks are autonomous code execution/posting and prompt-injection exposure from untrusted PR/repo content; install trust is only moderately concerning from the provided text alone.

Confidence: 83%Severity: 74%
Audit Metadata
Analyzed At
Mar 29, 2026, 10:38 PM
Package URL
pkg:socket/skills-sh/smallnest%2Fgoclaw%2Fcoding-agent%2F@6a9be3d4417f1c8d7e58bb75f6c9fa0ed0666f1f