swival

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is largely coherent with its stated purpose as a powerful delegated coding agent, but that purpose is itself high-impact: it combines command execution, broad file access, external provider/proxy communication, remote A2A connections, and optional secret handling. The main concerns are proportionality and trust boundaries rather than clear deception. Optional curl|bash installation for AgentFS and proxy/A2A routing raise supply-chain and data-flow risk, but there is no direct evidence here of credential harvesting or clearly malicious behavior.

Confidence: 83%Severity: 68%
Audit Metadata
Analyzed At
May 5, 2026, 06:45 PM
Package URL
pkg:socket/skills-sh/sheurich%2Fagent-skills%2Fswival%2F@14fd467900d144d93dc4f04106c56f032c6ad406