kairos-code
Warn
Audited by Socket on Mar 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s stated purpose is coherent, but it delegates execution to an unverifiable external KAIROS MCP server that can mint/update protocols and drive the agent through remote next_action steps. There is no direct credential harvesting or obvious malware behavior in the skill text, but the trust and remote-control model create meaningful security risk.
Confidence: 79%Severity: 63%
Audit Metadata