poteto-mode

Warn

Audited by Socket on Sep 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is presented as an agent style, but its actual footprint is much broader. It authorizes autonomous use of MCP tools, external updates, PR-driving, shipping workflows, and transitive skill routing. Those capabilities may fit an operations playbook, but they are disproportionate for a style-only skill. I do not see confirmed credential theft or covert exfiltration, so this is not malware, but it is a medium-high risk autonomy expansion with scope mismatch.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
Sep 8, 2026, 06:22 AM
Package URL
pkg:socket/skills-sh/theoklitosbam7%2Fpstack-portable%2Fpoteto-mode%2F@c0d255eda1a1d1f159d12ea02344e3c48a581499ddcc3f6d3faf3bc039e9f574
Security Audit — socket — poteto-mode