coding-agent

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill fragment is coherent with its stated purpose of orchestrating coding agents via PTY-backed Bash sessions for development workflows. It does not exhibit active malicious behavior or covert exfiltration in the fragment. The primary risk stems from powerful automation capabilities that, if not properly access-controlled and auditable, could be misused to push code or responses without explicit human review. Mitigations include enforcing least privilege, explicit approvals for PR actions, and strict session governance.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:15 AM
Package URL
pkg:socket/skills-sh/ThinkfleetAI%2Fthinkfleet-engine%2Fcoding-agent%2F@a0e47d81b74a454d34b7f1cda54bc06a6a3a8dc8