multitask

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s main behavior matches its stated purpose, but that purpose is inherently high-impact: autonomous parallel code modification and likely PR creation via subprocess agents. Data flows stay mostly local/GitHub-consistent and there is no clear credential-harvesting or exfiltration path, so this is not confirmed malware; however, the combination of broad command execution, multi-repo automation, and prompt-injection exposure makes it a high-risk skill.

Confidence: 82%Severity: 74%
Audit Metadata
Analyzed At
Mar 14, 2026, 03:27 PM
Package URL
pkg:socket/skills-sh/rysweet%2Famplihack%2Fmultitask%2F@eeae2b2a00690df7a2a12db23bd6c17b2b002c62