upgrade-v3
Warn
Audited by Socket on May 11, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core migration/editing behavior is coherent and same-org, but the skill’s footprint is broader than a typical refactor helper. Live verification reads local credentials, can trigger real external workflows, can invoke another skill, and may push/create GitHub PRs in the SDK repo. These behaviors are partially justified but materially increase trust and operational risk.
Confidence: 87%Severity: 61%
Audit Metadata