ntm

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's core orchestration purpose is coherent, but its footprint is high-risk. The main concerns are raw GitHub pipe-to-shell installation, built-in robot automation over multiple agents, arbitrary hook execution, and documented use of approval-bypass flags that weaken safety controls. This looks more like a legitimate but hazardous orchestration skill than confirmed malware.

Confidence: 84%Severity: 76%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:28 PM
Package URL
pkg:socket/skills-sh/dicklesworthstone%2Fagent_flywheel_clawdbot_skills_and_integrations%2Fntm%2F@e918aca3e9ddc38fe743fc3ed65146f0c3835f0f