coding-agent

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent, but its footprint is high-risk: it delegates broad shell/file authority to external coding-agent CLIs, encourages unsafe autonomy flags, and enables autonomous GitHub actions and PR handling on untrusted content. No clear credential-stealing or exfiltration behavior is present, so this is not confirmed malware, but the operational risk is materially above normal.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Mar 18, 2026, 11:22 PM
Package URL
pkg:socket/skills-sh/termix-official%2Fcryptoclaw%2Fcoding-agent%2F@6222a8790a6af6c7f61a3955fa1b84a57f1c5d6a