concierge

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core behavior mostly matches its stated concierge purpose, and the flagged command text is not load-time command injection. The main risk is operational autonomy combined with reliance on a non-official third-party Linear CLI that can receive Linear credentials for ticket and board actions; this is a coherent workflow, but the provenance and credential-forwarding make it medium-high risk rather than benign.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
Sep 16, 2026, 09:30 PM
Package URL
pkg:socket/skills-sh/coalesce-labs%2Fcatalyst-dev-skills%2Fconcierge%2F@d697ae994de6e19f60ad5153ce67c3c777dddcacfa3d75fa115df8f7b2e3249a
Security Audit — socket — concierge