dev-agent-spawn

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core Ghostty/tmux/AeroSpace footprint is coherent for a terminal agent spawner, and install sources appear official. Risk comes from its broad local control, default sandbox bypass via --dangerously-skip-permissions, arbitrary command injection into spawned sessions, transcript handling, and documented autonomous actions like git push/PR creation. This looks like a powerful but purpose-aligned orchestration skill, not confirmed malware.

Confidence: 82%Severity: 64%
Audit Metadata
Analyzed At
Mar 14, 2026, 09:36 PM
Package URL
pkg:socket/skills-sh/MOlechowski%2Fagent-skills%2Fdev-agent-spawn%2F@32d61949e9c75ca3b144098eda77546dbc3bcdc2