naga-config

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core purpose is coherent for a self-management skill, but it carries high-impact control over full config, prompt contents, MCP onboarding, and transitive skill installation. The main risk is not obvious malware; it is broad privileged reconfiguration, unpinned MCP package execution, arbitrary remote MCP endpoints, and prompt exposure/persistence.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
Mar 16, 2026, 07:40 AM
Package URL
pkg:socket/skills-sh/rtgs2017%2Fnagaagent%2Fnaga-config%2F@c6b39e84e662fdc59c51367d2228c8287ad694c6