dev-agent-spawn

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s core behavior matches its stated purpose and install sources are largely legitimate, but it intentionally spawns high-autonomy agent sessions using dangerous approval-bypass flags and supports arbitrary custom commands. The main risk is not hidden exfiltration; it is enabling powerful unattended local and repo-affecting actions through Ghostty/tmux orchestration.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Mar 15, 2026, 04:15 AM
Package URL
pkg:socket/skills-sh/molechowski%2Fclaude-skills%2Fdev-agent-spawn%2F@33e1e4c9947711863fb03d3a04db57c0fc6a6b1f