oneagent

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s core file-sync behavior matches its stated purpose, but it instructs unpinned `npx @latest` execution and, more importantly, installs additional third-party skills through a transitive trust chain. No credential harvesting or exfiltration is evident, so this is not malicious, but the install/execution trust is meaningfully risky.

Confidence: 84%Severity: 66%
Audit Metadata
Analyzed At
Mar 18, 2026, 11:26 PM
Package URL
pkg:socket/skills-sh/moskalakamil%2Foneagent%2Foneagent%2F@6718ea2de75b6bd46e21d0c4825d4fd82da3df03