anti-human-bottleneck

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is designed to make an AI agent act autonomously and to minimize human involvement, explicitly endorsing high-impact operations (git pushes, deployments, deletions, publishing, sending messages) without per-action human confirmation. While it contains no explicit code to exfiltrate data or install remote binaries, its instructions create a high operational risk: it enables autonomy abuse, potential destructive actions, and credential misuse because it encourages the agent to use available tools and credentials to perform irreversible changes. The lack of scoped permissions, safety checks, or explicit authorization flows makes this skill dangerous to enable in any environment where the agent has access to version control, deployment systems, messaging APIs, or package registries. I assess low probability of embedded malware code (no payloads or obfuscation observed), but high security risk due to the behavioral directives and potential for severe unintended or malicious actions if executed.

Confidence: 75%Severity: 85%
Audit Metadata
Analyzed At
Feb 28, 2026, 09:26 AM
Package URL
pkg:socket/skills-sh/nyosegawa%2Fskills%2Fanti-human-bottleneck%2F@e41c2d0264887aa66bcda7efa57aa672c6c8fdbd