benchmark-agents

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's benchmarking purpose mostly matches its actions, but it requires broad execution powers, installs a behavior-changing plugin from an unpinned GitHub source, and orchestrates multiple autonomous interactive agent sessions that can modify projects and perform account-linked setup. The main concern is high operational and transitive-trust risk, not confirmed malware.

Confidence: 84%Severity: 79%
Audit Metadata
Analyzed At
Mar 17, 2026, 09:26 AM
Package URL
pkg:socket/skills-sh/vercel%2Fvercel-plugin%2Fbenchmark-agents%2F@e8c0c2fa9036042f19b54a695ecf7c3dc0c8f459