unified-execute-with-file
Warn
Audited by Socket on Mar 25, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s overall purpose is coherent for a workflow executor, but its footprint is high-risk because it treats plan JSON as executable authority. Untrusted task content can drive Bash commands, file modifications, network-capable verification, commits, and transitive skill actions; this is disproportionate unless plans are fully trusted.
Confidence: 86%Severity: 78%
Audit Metadata