cmux-second-opinion
Warn
Audited by Socket on Apr 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core behavior is coherent with a second-opinion review skill, and there are no installer or obvious credential-theft patterns. However, it deliberately forwards local code/spec contents to another AI agent and launches that agent with approval-bypass flags, creating meaningful prompt-injection and delegated-action risk beyond a simple review helper.
Confidence: 82%Severity: 61%
Audit Metadata