autopilot
Warn
Audited by Socket on Sep 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The install path uses a legitimate ecosystem, but the skill's real footprint is unusually broad: it grants unattended execution across coding, deployment, E2E, review, and issue operations, and it relies on a transitive install of community-published skill content. This is not confirmed malware, but it is high-trust automation with meaningful supply-chain and operational risk disproportionate to normal helper skills.
Confidence: 90%Severity: 74%
Audit Metadata