coding-agent

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's capabilities mostly match its purpose of orchestrating coding-agent CLIs, and the cited Codex install path is official. The main risk is not hidden malware but high-impact autonomy: it encourages background execution, auto-approval modes, processing untrusted PR content, and public remote actions like push/comment/PR creation. This makes it a high-risk operational skill even though its purpose-capability alignment is largely coherent.

Confidence: 86%Severity: 76%
Audit Metadata
Analyzed At
Mar 28, 2026, 02:09 AM
Package URL
pkg:socket/skills-sh/malue-ai%2Fdazee-small%2Fcoding-agent%2F@ea1285a8a2eadc1cb03434d217b9006ecebd2501