polyphony

Warn

Audited by Socket on May 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the orchestration concept is coherent, but the actual trust boundary is not. The skill forwards host credentials into an unspecified container image and relies on an unverified core CLI/image source, making its footprint disproportionate and high risk even though Docker/GitHub tooling themselves are legitimate.

Confidence: 90%Severity: 88%
Audit Metadata
Analyzed At
May 11, 2026, 02:44 PM
Package URL
pkg:socket/skills-sh/alinaqi%2Fclaude-bootstrap%2Fpolyphony%2F@baab9fbfc7f69a11321083b2a6d4c6961939602d
Security Audit — socket — polyphony