ah-implement-tasks

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose is coherent for a coding orchestration skill, but its footprint is broader than a simple task implementer. Main concerns are transitive skill loading, ingestion of untrusted external content into write/exec-capable subagents, unpinned npx tooling, and automatic commits. No clear credential theft or exfiltration behavior is shown, so this is not malicious, but it is a medium-high risk automation skill.

Confidence: 88%Severity: 69%
Audit Metadata
Analyzed At
Apr 7, 2026, 11:37 AM
Package URL
pkg:socket/skills-sh/arinhubcom%2Farinhub-dev-skills%2Fah-implement-tasks%2F@7564a495dde7a3fca5a3427ba1b1093e0daea0d6
Security Audit — socket — ah-implement-tasks