os-improvement-loop

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent with its stated purpose as a local multi-agent improvement workflow, and I found no clear credential theft or external exfiltration. However, it has a broad autonomous local footprint, can rewrite its own instructions, and explicitly instructs transitive installation of another plugin/skill, which raises trust and integrity concerns beyond a purely descriptive documentation skill.

Confidence: 79%Severity: 56%
Audit Metadata
Analyzed At
Apr 3, 2026, 06:10 PM
Package URL
pkg:socket/skills-sh/richfrem%2Fagent-plugins-skills%2Fos-improvement-loop%2F@b63c5ebb2087255d495e4ce13b19f1b53e600f9e