autonomous-operation

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The file is not direct malware (no hard-coded secrets, obfuscated payloads, or explicit exfiltration), but it is structurally risky: it instructs agents to override safety constraints and to run/spawn actions that can modify external systems. In a supply-chain context this increases the attack surface and potential impact of compromised downstream skills or credentials. Only use with strict runtime guards, explicit human approvals, limited privileges, and auditability.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 03:05 AM
Package URL
pkg:socket/skills-sh/troykelly%2Fcodex-skills%2Fautonomous-operation%2F@889f14829c26b503ad6a96b4756d0b398aeec2ce