software-factory
Warn
Audited by Socket on Jul 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
This skill is coherent with its stated purpose as a design guide for autonomous AI workflows, so it is not malware. The main risk is that it operationalizes unattended agent loops with external actions and encourages composing additional skills/connectors, which raises autonomy and transitive-trust risk even though the documentation also recommends gates, blast-radius limits, and human approval for irreversible actions.
Confidence: 85%Severity: 68%
Audit Metadata