agent-export
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's purpose matches migration, but it asks the agent to export highly sensitive internal state—including persona/system-prompt-derived content and arbitrary files—and upload it to an unverified fly.dev relay. The main risk is data exfiltration and hidden-instruction leakage, not malware or installer abuse.
Confidence: 90%Severity: 82%
Audit Metadata