auto-perf-optimize
Warn
Audited by Socket on Apr 11, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is largely coherent with its stated VS Code performance-investigation purpose, but it carries meaningful security risk because it operates a real authenticated editor on the user's machine, can trigger real tool/file actions, and includes an unpinned third-party `npx agent-browser` execution path. This looks more like a legitimate but medium-risk automation skill than a credential-harvesting or overtly malicious one.
Confidence: 87%Severity: 62%
Audit Metadata