code-auto

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated purpose (end-to-end plan execution, testing, review, and finalize without user prompts) is coherent with its described workflow. It relies on internal plan parsing and established subagents, with no evident malicious download behavior or credential harvesting. The design is aligned with automated CI-like orchestration, though it introduces a high degree of autonomy that should be governed by repository policies and access controls. Overall, the footprint is BENIGN with MEDIUM-low security risk due to the autonomous execution and potential for unintended commits without explicit per-phase user confirmation in unknown contexts.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 07:59 PM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fcode-auto%2F@ddb521d3e50ae33b3fcadc67fa4faf4588a5b5c3