auto

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

No explicit malicious code or obfuscation present. The manifest describes a legitimate autonomous development loop that by design executes local commands and performs repository writes/commits. The primary security concern is the broad, unattended privileges granted to the agent (arbitrary quality_check execution, file writes, commits) combined with lack of enforced sandboxing, network restrictions, or secret-handling safeguards. This creates a moderate-to-high operational security risk when run in environments with credentials, network access, or attacker-writable repository files. Use only with strict isolation, least privilege, and human-in-the-loop controls.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 06:48 PM
Package URL
pkg:socket/skills-sh/ar4mirez%2Fsamuel%2Fauto%2F@2d046fd1f2dc2fd368c8cedab106db232da2e4da