foundation-evolve

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core behavior matches a repository-promotion workflow, and the only named external updater is an official CLI, so this is not confirmed malware. However, the skill is high-risk because it mandates autonomous commit/push to `main`, edits a separate hardcoded repository path, and propagates updates downstream via unpinned `npx skills update`.

Confidence: 89%Severity: 76%
Audit Metadata
Analyzed At
Sep 16, 2026, 08:46 PM
Package URL
pkg:socket/skills-sh/albertmartorell1975%2Fandroid-ai-workflow-foundation%2Ffoundation-evolve%2F@9bf4d6e736b71a303c1a8fd88988bb7b66e170084ac8aa33b63b57d666426aa5
Security Audit — socket — foundation-evolve