fleet

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s orchestration capabilities broadly match its stated purpose, but its trust and scope are high risk: it relies on an unverified core CLI (`azlin`), forwards GitHub/Azure/Claude credentials to remote VMs, and enables autonomous actions across sessions using broad transcript capture. No clear malicious exfiltration endpoint is shown, but the combination of unverifiable dependency, credential propagation, and autonomous remote control makes this a high-risk skill.

Confidence: 85%Severity: 84%
Audit Metadata
Analyzed At
Mar 14, 2026, 03:26 PM
Package URL
pkg:socket/skills-sh/rysweet%2Famplihack%2Ffleet%2F@17b60cdb86b46de334be7125886774464f88c395