poteto-mode
Warn
Audited by Socket on Sep 8, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is presented as an agent style, but its actual footprint is much broader. It authorizes autonomous use of MCP tools, external updates, PR-driving, shipping workflows, and transitive skill routing. Those capabilities may fit an operations playbook, but they are disproportionate for a style-only skill. I do not see confirmed credential theft or covert exfiltration, so this is not malware, but it is a medium-high risk autonomy expansion with scope mismatch.
Confidence: 88%Severity: 68%
Audit Metadata