vs-autopilot

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated purpose, but its footprint is high-risk because it enables broad autonomous code execution and repository modification with effectively no per-action approval. There is no clear credential harvesting or exfiltration behavior, so this is not confirmed malware, but the autonomy, dynamic loading of other skills, and prompt-injection exposure make it a high-risk agent skill.

Confidence: 89%Severity: 79%
Audit Metadata
Analyzed At
Apr 1, 2026, 03:14 PM
Package URL
pkg:socket/skills-sh/vltansky%2Fvladstack%2Fvs-autopilot%2F@5f8569940cf2f27ee3cb221adceaa3b1ffa427b2
Security Audit — socket — vs-autopilot