vscode-terminal-autoapprove
Fail
Audited by Socket on Mar 9, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The skill's stated purpose is to guide configuring a feature that auto-approves terminal commands. While this is helpful for advanced users, the capability inherently introduces security risk by bypassing per-command confirmation, especially if attackers exploit crafted inputs to Copilot Chat. The documentation and config examples are coherent with its purpose but warrant caution: auto-approval should be tightly scoped, include explicit whitelisting, and ideally require user review for high-risk commands. Overall, the footprint is plausible for a guidance/documentation skill but is moderately risky in practice due to potential command execution without user prompts.
Confidence: 98%
Audit Metadata