autodev

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s core behavior matches its stated purpose, but it grants an AI agent autonomous multi-session coding and automatic git commits, plus configurable shell execution and transitive use of other skills. There is no clear credential theft or external exfiltration path, so this is not malware, but it is a high-risk autonomous repo-modification skill.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
Mar 27, 2026, 01:46 AM
Package URL
pkg:socket/skills-sh/jh941213%2Fmy-claude-code-asset%2Fautodev%2F@bb53bfc6af15a863dec001dabbf28ebec86ed8e5