aap-automation
Warn
Audited by Socket on May 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill’s capabilities largely match its stated AAP automation purpose, but it carries meaningful risk because it grants an agent privileged infrastructure control and is distributed from an unverified personal GitHub repo rather than a clearly official publisher. No clear credential exfiltration is described, so this is better classified as suspicious/high-risk operational tooling than malware.
Confidence: 80%Severity: 74%
Audit Metadata