gate
Warn
Audited by Socket on May 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core review-and-gate behavior matches the stated purpose, but the skill expands trust by instructing installation of multiple third-party skills and by ingesting broad contextual data such as past session history and PR/issue comments into agent prompts. This is not clearly malicious, but the transitive skill installation and prompt-injection/supply-chain exposure make the footprint riskier than a typical read-only quality gate.
Confidence: 84%Severity: 66%
Audit Metadata