agentation

Fail

Audited by Socket on Mar 29, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the file-editing portion matches the stated Next.js toolbar setup, but the skill also installs and auto-registers an external MCP server via unpinned `npx`, expanding trust and creating an unclear data path. The main concern is supply-chain and transitive tool installation rather than confirmed malware.

Confidence: 82%Severity: 74%
Audit Metadata
Analyzed At
Mar 29, 2026, 07:08 AM
Package URL
pkg:socket/skills-sh/somtougeh%2Fdotfiles%2Fagentation%2F@40b693adee674d717508bcc607da07aafec6c1db
Security Audit — socket — agentation