church-anchor
Warn
Audited by Socket on May 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s purpose is coherent, but it depends on a required church CLI whose provenance and official distribution could not be verified from the evidence. It also allows the agent to mutate workflow state, so the main issue is high supply-chain trust risk from an undocumented executable rather than overt malicious behavior.
Confidence: 83%Severity: 78%
Audit Metadata