church-harden

Warn

Audited by Socket on May 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent, but the skill’s core footprint depends on an unverified `church` CLI that reads repo content and may influence planning without any verifiable install source, publisher relationship, or documented data flows. No explicit credential theft or malicious endpoint is shown, but the opaque binary and unspecified research/network path make the skill high security risk.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
May 15, 2026, 04:42 PM
Package URL
pkg:socket/skills-sh/chendrizzy%2Frepo-church%2Fchurch-harden%2F@e239c6e1a060e64faa064b5204aa343b403e6ab2
Security Audit — socket — church-harden