continuous-improvement

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Suspicious due to transitive trust: the orchestrator itself is narrow, but its stated purpose relies on spawning unreviewed subskills and passing them local context. No direct credential theft or explicit exfiltration is visible in this file, yet the unverifiable delegated execution makes the overall skill high-risk relative to its simple orchestration role.

Confidence: 80%Severity: 72%
Audit Metadata
Analyzed At
Apr 24, 2026, 05:55 PM
Package URL
pkg:socket/skills-sh/bug-ops%2Fclaude-plugins%2Fcontinuous-improvement%2F@84ffbd45077c59479babea8f5a0f00cce0e2c630
Security Audit — socket — continuous-improvement