coding-agent

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The fragment is a coherent automation blueprint for orchestrating multiple AI coding agents in isolated workspaces with background execution and PR workflows. While not inherently malicious, the configuration embodies governance and supply-chain risk due to autonomous agent modes (--yolo), reliance on third-party tools, and data exchange with external AI providers. Recommended mitigations: restrict autonomous modes, implement explicit per-action approvals, enforce least-privilege API access, enforce strong secret management, and enable comprehensive activity logging and audit trails for all agent invocations and GitHub interactions.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 3, 2026, 04:43 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fcoding-agent%2F@accc99497c3ad495d103398a4a659166bd3d4368