using-oac

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the file is internally consistent as a workflow/meta-skill, but its actual effect is to compel transitive loading of other skills before any response and to reduce agent discretion. There is no direct malware behavior, credential access, network exfiltration, or installer risk in this file alone, but the forced trust chain makes it a medium-risk control-layer skill.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Mar 14, 2026, 07:09 PM
Package URL
pkg:socket/skills-sh/darrenhinde%2Fopencode-agents%2Fusing-oac%2F@ef9eebe45bc75498d74701c850f7b1ca6c03f749