paseo-loop

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned but materially high-risk because it operationalizes persistent autonomous agent loops, allows transitive capability expansion through another skill, and can act on untrusted external content while modifying code or running commands. No clear credential theft or malicious exfiltration is shown in this fragment, so this is high vulnerability risk rather than confirmed malware.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Mar 15, 2026, 02:11 PM
Package URL
pkg:socket/skills-sh/getpaseo%2Fpaseo%2Fpaseo-loop%2F@0054917fcbbf2b65b95795603c2f161d14a53849