ai-collab-dev

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's workflow purpose is coherent, but it materially increases risk by combining unattended agent operation, commit-capable execution, transitive trust in another skill, and ingestion of external AI-generated content into an agent that can write and run code. No clear credential theft or exfiltration is shown, so this is not confirmed malware, but it is a high-risk autonomous workflow skill.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Apr 8, 2026, 02:47 PM
Package URL
pkg:socket/skills-sh/wojons%2Fskills%2Fai-collab-dev%2F@bc88879f47061721037f0093fa6786fe49c52802