coding-agent

Fail

Audited by Socket on Mar 6, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The fragment presents a coherent, purpose-aligned pattern to orchestrate interactive coding agents using PTY-enabled Bash sessions. It does not inherently exfiltrate data or embed credentials, but it does introduce significant operational power through external tooling and session management. With proper sandboxing, credential management, and strict access control over workdirs and network operations, the risk remains moderate. The analysis should guide secure usage and approvals for tooling in real environments.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Mar 6, 2026, 06:19 PM
Package URL
pkg:socket/skills-sh/termix-official%2Fcryptoclaw%2Fcoding-agent%2F@6222a8790a6af6c7f61a3955fa1b84a57f1c5d6a