brainstorm

Warn

Audited by Socket on Apr 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's core brainstorming purpose is legitimate and there is no evidence of credential theft, malicious exfiltration, or untrusted external installers. However, its footprint is broader than necessary for that purpose: wildcard Skill(*) delegation, full Bash(*) access, and explicit auto-continue/no-stop workflow autonomy create a disproportionate trust surface for a planning skill.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
Apr 25, 2026, 10:12 AM
Package URL
pkg:socket/skills-sh/catlog22%2Fclaude-code-workflow%2Fbrainstorm%2F@c6cad9812fdce5465bfd7d0abb8e7435347b6509
Security Audit — socket — brainstorm