Code Cog
PassAudited by VirusTotal on Apr 23, 2026.
Findings (1)
The code-cog skill facilitates arbitrary shell command execution and local file system access (read/write/edit) via the cellcog SDK and a required desktop application. While these high-risk capabilities are aligned with the stated purpose of a coding agent, the documentation in SKILL.md explicitly describes features like HumanComputer_Terminal and direct machine access, which present a significant security risk if the underlying AI or the cellcog service is compromised. No evidence of intentional malice was found, but the broad permissions and reliance on external binaries/APIs meet the threshold for a suspicious classification.
