autopilot

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated purpose, but its footprint is high risk because it turns untrusted issue content into autonomous code execution, repo modification, and PR creation. No clear credential harvesting or exfiltration appears, so this looks more like an overpowered automation skill than confirmed malware.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:38 PM
Package URL
pkg:socket/skills-sh/phrazzld%2Fclaude-config%2Fautopilot%2F@88299e67cefc495c9b242290d749a52cdfb602b2