agentation

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core capability is coherent with a UI annotation skill, and most data flow is local-first, but the footprint is broader than a simple UI helper: it installs/executes npm packages via unpinned `npx`, modifies multiple agent configs, supports transitive skill installation, enables autonomous edit loops, and can forward annotation data to arbitrary webhooks. This looks more like high-risk automation tooling than outright malware.

Confidence: 82%Severity: 66%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:48 PM
Package URL
pkg:socket/skills-sh/supercent-io%2Fskills-template%2Fagentation%2F@bc3e3889a6397fbdc2be5e2e559f40d6c68f5ced