automation

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core skill is purpose-aligned and uses official OpenHands API endpoints, so it is not overtly malicious. Risk comes from autonomous scheduled execution with full sandbox/secrets access and from transitive trust in external plugins fetched from arbitrary repos or git URLs, especially when mutable refs are allowed.

Confidence: 85%Severity: 66%
Audit Metadata
Analyzed At
Apr 12, 2026, 06:15 PM
Package URL
pkg:socket/skills-sh/openhands%2Fskills%2Fautomation%2F@b404c2248a39dc185f5466f15e77907282cabefb