ov-kanban
Audited by Socket on Oct 2, 2026
2 alerts found:
Securityx2SUSPICIOUS. The core kanban storage behavior is coherent with the stated purpose, but the optional loop materially expands scope: it runs an agent autonomously, bypasses approvals/sandbox by default, and executes a templated command through eval. No clear credential theft or off-purpose exfiltration is shown, so this is not confirmed malware, but it is a high-risk workflow skill due to autonomous execution and command-template injection surface.
This is a task-loop wrapper rather than evident malware. However, its default command disables agent approval and sandbox protections, and eval makes the configurable command an arbitrary shell-execution point. Use only with trusted configuration and task sources, or remove eval and retain execution sandboxing.