pua-loop

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s footprint is dominated by autonomous hook-driven execution, explicit suppression of user checkpoints, and transitive trust in another skill. There is no clear credential exfiltration or malicious network routing in the provided text, but the autonomy model and unverified local setup script make it high security risk for an AI agent environment.

Confidence: 87%Severity: 82%
Audit Metadata
Analyzed At
Mar 23, 2026, 02:02 PM
Package URL
pkg:socket/skills-sh/tanweai%2Fpua%2Fpua-loop%2F@4e81d132fb8d1fb0b7a250562d18c98b446905a9