to-product

Warn

Audited by Socket on Jul 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s capabilities are aligned with an autonomous delivery orchestrator, but its scope is unusually broad and it is intentionally non-interactive, allowing the agent to make owner decisions, modify the repo, merge changes, and delete branches without per-action approval. No clear malware or credential-exfiltration behavior is shown, and install trust appears limited to local repo code plus Node, but the autonomous real-world action scope and transitive trust in many internal skills make this high risk.

Confidence: 92%Severity: 81%
Audit Metadata
Analyzed At
Jul 29, 2026, 09:30 AM
Package URL
pkg:socket/skills-sh/beeltec%2Fskills%2Fto-product%2F@9452f96e2fa323a230f73b85395df174cfc82c0c8775f6a9459cb9edabdf713a
Security Audit — socket — to-product