agent-loop
Warn
Audited by Socket on Apr 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s core workflow is coherent for software delivery, but it meaningfully expands agent authority through autonomous repo/tracker actions and transitive skill/plugin installation. No clear credential theft or covert exfiltration appears, so this is not malware, but it carries medium security risk from delegated external actions and inherited trust.
Confidence: 82%Severity: 60%
Audit Metadata