agentation

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: mostly coherent with a UI annotation/MCP purpose, but the footprint is broader than a simple React helper. Main concerns are transitive skill installation, unpinned npx execution, third-party installer chaining, multi-agent config modification, and autonomous watch-loop behavior. Data flow is largely local and purpose-aligned, so this is not confirmed malicious.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
Mar 20, 2026, 07:01 AM
Package URL
pkg:socket/skills-sh/JEO-tech-ai%2Foh-my-gods%2Fagentation%2F@9c32f379fd7d99f0adc1469e81b5a43e164d8ea8