vscode-terminal-autoapprove

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated purpose is to guide configuring a feature that auto-approves terminal commands. While this is helpful for advanced users, the capability inherently introduces security risk by bypassing per-command confirmation, especially if attackers exploit crafted inputs to Copilot Chat. The documentation and config examples are coherent with its purpose but warrant caution: auto-approval should be tightly scoped, include explicit whitelisting, and ideally require user review for high-risk commands. Overall, the footprint is plausible for a guidance/documentation skill but is moderately risky in practice due to potential command execution without user prompts.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 11:18 PM
Package URL
pkg:socket/skills-sh/arisng%2Fgithub-copilot-fc%2Fvscode-terminal-autoapprove%2F@7525c43956d31718cbb780dc51ca900866f65520