Coding Agent
PassAudited by VirusTotal on Apr 1, 2026.
Findings (1)
The skill bundle provides instructions for delegating tasks to external coding agents (Codex, Claude Code, etc.) using high-risk configurations. Specifically, SKILL.md encourages the use of the '--yolo' flag (disabling sandboxes and approvals) and the 'elevated: true' parameter (running on the host instead of a sandbox). While these are presented as features for 'iterative coding,' they allow unvetted third-party agents full, non-interactive access to the host system. No explicit evidence of data exfiltration or intentional malice was found, but the promotion of bypassing security controls for background processes is highly risky.
