auto-trigger

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent as a workflow hook/config skill, but its real effect is to auto-invoke other skills transitively, including background/self-improving chains and auto session logging. No direct credential theft or exfiltration is visible, yet the orchestration model expands agent autonomy and trust beyond this skill's own narrow permissions.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/charon-fan%2Fagent-playbook%2Fauto-trigger%2F@a2e16b67041e6a67a32d0e9f6bcc0de5ed94627a