execute-subtask-direct
Warn
Audited by Socket on Apr 8, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core workflow mostly matches its stated purpose, but it enables autonomous commit/push/task-completion actions and relies on an external `agkan` CLI whose provenance is not clearly verified in the provided evidence. No strong signs of credential theft or covert exfiltration are present, so this is not malware, but it carries medium security risk.
Confidence: 87%Severity: 58%
Audit Metadata