build-in-public
Warn
Audited by Socket on Jul 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Mostly coherent and purpose-aligned: it gathers project-scoped work evidence and drafts a status update without auto-posting. The main concern is install/execution trust from requiring external CLIs—especially a likely third-party `linear` client and an opaque `devsql` tool—so this is best classified as suspicious/medium-high risk on supply-chain grounds rather than malicious behavior.
Confidence: 85%Severity: 72%
Audit Metadata