retrospective
Warn
Audited by Socket on Apr 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally coherent for a retrospective workflow, and its only named execution dependency (uv) appears official and proportionate. The main risk is that it ingests raw, potentially attacker-influenced engagement transcripts and reasoning logs, then uses that material to produce reports and edit local skill files, creating a meaningful indirect prompt-injection and offensive-workflow risk even without overt exfiltration.
Confidence: 86%Severity: 72%
Audit Metadata