iterate

Warn

Audited by Socket on Apr 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

BENIGN in purpose/data-flow alignment but medium-risk operationally. It uses official GitHub tooling and official endpoints only, with no suspicious installer or third-party credential routing; however, it gives the agent substantial autonomous repository powers and lets external GitHub comments/logs influence code edits and actions, so the main risk is autonomous action plus indirect prompt injection rather than malware.

Confidence: 90%Severity: 64%
Audit Metadata
Analyzed At
Apr 25, 2026, 01:33 PM
Package URL
pkg:socket/skills-sh/openhands%2Fskills%2Fiterate%2F@5a26c4457bcdff5398334b605ddddb0c0b39e9a4