grunk

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose aligns with repo-task automation, but its footprint is high-risk because it can autonomously turn external task content into code changes, shell execution, git pushes, and task-state updates. Dependency provenance for `bd` appears coherent and same-project, so the main concern is autonomous action and trust chaining, not obvious malware or credential theft.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
Apr 27, 2026, 05:20 PM
Package URL
pkg:socket/skills-sh/BvdMerwe%2Ftrogteam%2Fgrunk%2F@a8430a4101c71d182eb42ce1724493dda4aaf65b