coding-agent

Warn

Audited by Socket on Apr 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is coherent with its stated purpose of orchestrating coding-agent CLIs, and the verified install paths for Claude Code and Codex are official and proportionate. The main risk is not hidden exfiltration but high-autonomy execution: it instructs agents to run with permission-bypass modes, modify code, review untrusted PR content, and even push branches or create/comment on PRs. Overall this looks legitimate but high-impact, so it is best classified as suspicious/high-risk operationally rather than malicious.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
Apr 25, 2026, 12:23 PM
Package URL
pkg:socket/skills-sh/steipete%2Fclawdis%2Fcoding-agent%2F@74a67fc7ac9f2ebba785c8b7be4770070d277e80