cook-auto

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose matches coding automation, but it materially increases risk by removing normal confirmations, invoking opaque local slash commands, and chaining into other local skills. No clear credential theft or external exfiltration is present, so this is not confirmed malware; the main concern is high-impact autonomous local execution with transitive trust.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Mar 21, 2026, 03:50 AM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fcook-auto%2F@15db9555a93110de34c8392e469f33627cb7c7d6