coding-agent

Fail

Audited by Socket on Apr 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill is purpose-aligned, but it grants broad delegated execution to external coding-agent CLIs, encourages high-autonomy modes, and processes untrusted PR/repo content with write/exec capability. No clear credential theft or malicious exfiltration is present, but the operational risk is medium due to autonomous actions and third-party CLI trust.

Confidence: 80%Severity: 66%
Audit Metadata
Analyzed At
Apr 18, 2026, 12:42 PM
Package URL
pkg:socket/skills-sh/firecrawl%2Fopenclaw%2Fcoding-agent%2F@6222a8790a6af6c7f61a3955fa1b84a57f1c5d6a