stampede
Warn
Audited by Socket on Aug 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent for autonomous issue orchestration, and its main tool dependencies appear official. The main risks are high-impact autonomous actions (merging, commenting, relabeling, closing issues/PRs) and reliance on external CLIs with broad repo/tracker authority; install hygiene for herdr/worktrunk is also weaker where curl|sh is used. I found no strong evidence of credential theft, covert exfiltration, or malicious misdirection.
Confidence: 88%Severity: 72%
Audit Metadata