cook-auto-fast
Warn
Audited by Socket on Mar 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core coding purpose is plausible, but the footprint is broader than a simple implementation helper because it enables autonomous execution without confirmation, loads additional local skills transitively, and processes untrusted repo content before taking write actions. No direct credential theft, exfiltration endpoint, or malicious installer is evident in this snippet, so this is not confirmed malware; the main concern is operational and transitive-trust risk.
Confidence: 88%Severity: 71%
Audit Metadata