dev-agent-spawn
Warn
Audited by Socket on Mar 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s core behavior matches its stated purpose and install sources are largely legitimate, but it intentionally spawns high-autonomy agent sessions using dangerous approval-bypass flags and supports arbitrary custom commands. The main risk is not hidden exfiltration; it is enabling powerful unattended local and repo-affecting actions through Ghostty/tmux orchestration.
Confidence: 87%Severity: 72%
Audit Metadata