auto-task

Warn

Audited by Socket on May 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose matches autonomous task orchestration, but its footprint is very broad for a generic workflow skill. The main risk is not malware or credential theft; it is underconstrained autonomy with web/sub-agent/MCP ingestion plus Bash and file-write access, which creates meaningful prompt-injection and unsafe-action exposure.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
May 14, 2026, 06:54 AM
Package URL
pkg:socket/skills-sh/yunshu0909%2Fyunshu_skillshub%2Fauto-task%2F@2c943fdd844e00882866082288bbcdf120c1ef8a
Security Audit — socket — auto-task