cmux-second-opinion

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core behavior is coherent with a second-opinion review skill, and there are no installer or obvious credential-theft patterns. However, it deliberately forwards local code/spec contents to another AI agent and launches that agent with approval-bypass flags, creating meaningful prompt-injection and delegated-action risk beyond a simple review helper.

Confidence: 82%Severity: 61%
Audit Metadata
Analyzed At
Apr 14, 2026, 05:53 PM
Package URL
pkg:socket/skills-sh/anyoneanderson%2Fagent-skills%2Fcmux-second-opinion%2F@7ae1521b0491c0aed079eb19033aff7f5eecb0d6