naga-config
Warn
Audited by Socket on Mar 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core purpose is coherent for a self-management skill, but it carries high-impact control over full config, prompt contents, MCP onboarding, and transitive skill installation. The main risk is not obvious malware; it is broad privileged reconfiguration, unpinned MCP package execution, arbitrary remote MCP endpoints, and prompt exposure/persistence.
Confidence: 88%Severity: 78%
Audit Metadata