kairos-code

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s stated purpose is coherent, but it delegates execution to an unverifiable external KAIROS MCP server that can mint/update protocols and drive the agent through remote next_action steps. There is no direct credential harvesting or obvious malware behavior in the skill text, but the trust and remote-control model create meaningful security risk.

Confidence: 79%Severity: 63%
Audit Metadata
Analyzed At
Mar 13, 2026, 07:44 AM
Package URL
pkg:socket/skills-sh/debian777%2Fkairos-mcp%2Fkairos-code%2F@5c545f6f8f6386a2e42ab7fef14251ef682213a8