mac-code-local-ai-agent

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core capabilities mostly fit a local coding-agent skill, but the footprint is still risky: model-generated shell execution, file access, and web-search ingestion create a credible prompt-to-command path, and the claimed publisher does not match the referenced GitHub repo. Supply-chain trust is medium rather than extreme because dependencies are from common registries and Hugging Face, but overall the skill grants high-impact local actions that exceed a low-risk documentation/tooling profile.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Mar 27, 2026, 01:43 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fmac-code-local-ai-agent%2F@856323f8044b8eabd05f222cf2c6373201f9146f