awesome-code

Fail

Audited by Socket on Mar 9, 2026

2 alerts found:

Obfuscated Filex2
Obfuscated FileHIGH
agents/multi-agent-coordinator/SKILL.md

The multi-agent coordinator skill is conceptually coherent with its stated purpose: it aims to decompose complex tasks, dispatch to subagents, enforce quality gates, and aggregate results across orchestrator/peer-to-peer/pipeline modes. The fragment does not specify dangerous downloads, credential handling, or exfiltration paths. However, there are sensible gaps to address in implementation, notably explicit handling of credentials/secrets, explicit security criteria for the review gates, data handling/logging policies, and safeguarding against unintended autonomous actions beyond user intent. Overall, the footprint is benign but warrants careful implementation to avoid credential exposure, data leakage via logs, or unbounded autonomous behavior. Security risk is low-to-medium pending concrete implementation details; treat as Suspicious until formalized guardrails are in place.

Confidence: 98%
Obfuscated FileHIGH
agents/documentation-specialist/SKILL.md

The Documentation Specialist skill is coherently aligned with its stated purpose. It focuses on producing usable, maintainable documentation and ensuring alignment with interface contracts, without engaging in credential access, code execution, or data exfiltration. The risk footprint is minimal and proportionate to documentation tooling activities. Overall, the skill appears benign with respect to security concerns; no suspicious install/download patterns or credential flows detected.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 07:31 AM
Package URL
pkg:socket/skills-sh/huangwb8%2Fskills%2Fawesome-code%2F@b037b455ba14bc7488c94e0ae4e9f7a71d26ab92