babysit

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core babysitter orchestration behavior mostly matches the stated purpose, and the main SDK install path is plausibly legitimate. However, the skill is high-privilege, directs the agent to install additional skills/subagents, and mixes untrusted web/repo research with file writes and command execution, creating meaningful transitive-trust and prompt-injection risk even without clear exfiltration behavior.

Confidence: 84%Severity: 71%
Audit Metadata
Analyzed At
Apr 1, 2026, 02:09 PM
Package URL
pkg:socket/skills-sh/a5c-ai%2Fbabysitter%2Fbabysit%2F@d1c5290a3d85e6c0572953a77005eec2974e3be7