coding-agent-2
Warn
Audited by Socket on Mar 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is purpose-aligned for orchestrating coding-agent CLIs, but it materially increases risk by combining untrusted code/PR ingestion with write/exec-capable agents and by endorsing highly autonomous modes that can push code and create PRs. This looks more risky than malicious: coherent for its stated purpose, but still a high-impact orchestration skill that should be treated as suspicious/high-risk rather than benign.
Confidence: 87%Severity: 66%
Audit Metadata