agent-messaging
Fail
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS: The capability mostly matches the stated purpose, but the install model requires executing an unreviewed repo script and the external messaging/provider data flows are underspecified. This looks more like a plausible but higher-trust messaging skill than confirmed malware.
Confidence: 80%Severity: 56%
Audit Metadata