foundation-evolve
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core behavior matches a repository-promotion workflow, and the only named external updater is an official CLI, so this is not confirmed malware. However, the skill is high-risk because it mandates autonomous commit/push to `main`, edits a separate hardcoded repository path, and propagates updates downstream via unpinned `npx skills update`.
Confidence: 89%Severity: 76%
Audit Metadata