agentation

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core functionality is coherent for a UI-annotation skill, and most installs/data flows are plausibly aligned with that purpose. However, risk is materially elevated by transitive skill installation, unpinned `npx -y` execution, auto-running agent hooks, autonomous watch-loop behavior, and optional forwarding of annotation data to arbitrary webhook endpoints.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 16, 2026, 08:02 AM
Package URL
pkg:socket/skills-sh/akillness%2Foh-my-skills%2Fagentation%2F@0cb003a4ce5f4bdcd7e1d5b228d34d85132c82fc