looping-tasks

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's core purpose matches autonomous implementation loops, and its tooling/data flows are mostly coherent and same-org. However, default `--dangerously-skip-permissions`, repeated fresh-session automation, ingestion of untrusted repo content, and automatic `git push` create a high-risk autonomous workflow that can make and publish changes without per-step user approval.

Confidence: 91%Severity: 74%
Audit Metadata
Analyzed At
Mar 14, 2026, 08:25 AM
Package URL
pkg:socket/skills-sh/riccardogrin%2Fskills%2Flooping-tasks%2F@18a9b5dd2506e811f6341ee133bcd74f9e5b2f42