church-spec-gate

Warn

Audited by Socket on May 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose is coherent, but it depends on an unverifiable local `church` executable with repo-modifying capabilities and no trustworthy install/provenance details in the skill. No direct credential theft or exfiltration is shown, but the unknown CLI creates a high supply-chain risk.

Confidence: 82%Severity: 78%
Audit Metadata
Analyzed At
May 15, 2026, 04:42 PM
Package URL
pkg:socket/skills-sh/chendrizzy%2Frepo-church%2Fchurch-spec-gate%2F@9d545dc7c6e550f85a9f4a2c035cbca5a7d30da1
Security Audit — socket — church-spec-gate