church-gap-closure

Warn

Audited by Socket on May 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose is coherent, but it relies on an unverifiable `church` CLI with unclear provenance and authority to modify project governance state. No direct credential theft or exfiltration is shown, so this is better classified as medium/high security risk from trust and opaque execution rather than confirmed malware.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
May 15, 2026, 04:42 PM
Package URL
pkg:socket/skills-sh/chendrizzy%2Frepo-church%2Fchurch-gap-closure%2F@ce0cefe1088e3ad9ead72c14110a61c90524d04a
Security Audit — socket — church-gap-closure