coding-agent

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill's stated purpose (facilitating advanced coding tasks via interactive agents in PTY-enabled bash sessions) is generally coherent with its capabilities and described workflow. Data flows are largely confined to local workdirs and standard collaboration endpoints (GitHub). There is a mild elevated risk around aggressive automation flags and background autonomous work, but no explicit credential handling or hidden data exfiltration is evident from the description. Overall, the footprint is plausible and proportionate to the coding task focus, with attention recommended on controlling auto-approval modes and ensuring secure handling of repository access and secrets.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Mar 12, 2026, 02:38 AM
Package URL
pkg:socket/skills-sh/Gen-Verse%2FOpenClaw-RL%2Fcoding-agent%2F@6222a8790a6af6c7f61a3955fa1b84a57f1c5d6a