coding-agent
Fail
Audited by Socket on Mar 6, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
The fragment presents a coherent, purpose-aligned pattern to orchestrate interactive coding agents using PTY-enabled Bash sessions. It does not inherently exfiltrate data or embed credentials, but it does introduce significant operational power through external tooling and session management. With proper sandboxing, credential management, and strict access control over workdirs and network operations, the risk remains moderate. The analysis should guide secure usage and approvals for tooling in real environments.
Confidence: 98%Severity: 55%
Audit Metadata