os-eval-runner
Warn
Audited by Socket on Apr 3, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s core local evaluation purpose is plausible, but its actual footprint is broader than necessary. Autonomous mutation/commit/push behavior, transitive skill installation, destructive cleanup commands, and forwarding project content to external proposer CLIs make the scope disproportionate to a stateless evaluator.
Confidence: 89%Severity: 78%
Audit Metadata