evolution
Warn
Audited by Socket on Apr 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's self-evolution goal matches its file-editing and hook behavior, but the footprint is still high-risk. The main concerns are persistent auto-triggered hooks, autonomous self-modification, and dynamic skill loading; the curl|bash installer is official to the same repo but remains a notable supply-chain weakness.
Confidence: 84%Severity: 71%
Audit Metadata