coding-agent

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Overall, the manifest is benign and purpose-aligned for its stated use-case of orchestrating coding agents for development tasks. The principal security considerations are operational risk and potential exposure of repository contents through temp workspaces if misused in shared environments, rather than explicit credential theft or data exfiltration. Recommend safeguards such as per-action prompts, mandatory human review for destructive actions, scoped permissions for PR operations, and comprehensive audit logging to mitigate operational risk while preserving productivity.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 02:42 PM
Package URL
pkg:socket/skills-sh/steipete%2Fclawdis%2Fcoding-agent%2F@ac9358bb521fdbcaebf4faea19fbf93a1f3a5937