coding-workflow
Warn
Audited by Socket on Apr 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core workflow guidance is benign and proportionate, but the skill expands trust by instructing installation of multiple external companion skills, including one with weaker provenance. Main risk is transitive skill installation and moderate remote supply-chain exposure, not direct credential theft or overtly malicious behavior.
Confidence: 88%Severity: 64%
Audit Metadata