paseo-handoff

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but it expands trust by requiring another skill, launches detached downstream agents with broad execution modes, and forwards comprehensive context to external tooling. The Paseo CLI appears official and npm-distributed, so this is not strong evidence of malware, but it is a meaningful agent-autonomy and delegated-trust risk.

Confidence: 84%Severity: 66%
Audit Metadata
Analyzed At
Mar 15, 2026, 02:11 PM
Package URL
pkg:socket/skills-sh/getpaseo%2Fpaseo%2Fpaseo-handoff%2F@8b2ee9d8f6f072181607b089ac78e0f34bfa8964