church-anchor

Warn

Audited by Socket on May 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose is coherent, but it depends on a required church CLI whose provenance and official distribution could not be verified from the evidence. It also allows the agent to mutate workflow state, so the main issue is high supply-chain trust risk from an undocumented executable rather than overt malicious behavior.

Confidence: 83%Severity: 78%
Audit Metadata
Analyzed At
May 15, 2026, 04:42 PM
Package URL
pkg:socket/skills-sh/chendrizzy%2Frepo-church%2Fchurch-anchor%2F@6e11c7003cd154d952486f98f7c20da34692ae18
Security Audit — socket — church-anchor