auto-project-runner

Warn

Audited by Socket on Feb 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is conceptually aligned with autonomous project work, memory-driven task execution, and minimal prompts. However, the high-autonomy settings (auto_accept_permissions and 30 concurrent tasks) introduce significant risk of unintended disruptive edits. No external data leakage is evident, but operational safeguards are essential. Treat as BENIGN with HIGH CONTEXTUAL RISK (suspiciously autonomous) until explicit safeguards (versioned commits, per-change confirmations for destructive operations, restricted permissions, and robust audit trails) are in place.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 24, 2026, 11:50 PM
Package URL
pkg:socket/skills-sh/tippyentertainment%2Fskills%2Fauto-project-runner%2F@3ebe31cebd23dfd8344f33b79176b6286d9aa257