agentation
Fail
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS: the file-editing portion matches the stated Next.js toolbar setup, but the skill also installs and auto-registers an external MCP server via unpinned `npx`, expanding trust and creating an unclear data path. The main concern is supply-chain and transitive tool installation rather than confirmed malware.
Confidence: 82%Severity: 74%
Audit Metadata