ulw-loop

Warn

Audited by Socket on Jun 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The visible skill is broadly consistent with a goal-execution workflow, but it delegates critical behavior to an unseen full-workflow file and to undocumented local CLIs while granting high operational autonomy through background subagents, QA, and git commits. No clear credential theft or exfiltration is shown, so this is not malicious from the provided text, but the hidden workflow and tool provenance make the footprint moderately risky.

Confidence: 79%Severity: 58%
Audit Metadata
Analyzed At
Jun 23, 2026, 11:37 AM
Package URL
pkg:socket/skills-sh/code-yeongyu%2Flazycodex%2Fulw-loop%2F@90972422c9e1331a9348d88ba41e0a2e668b101427513f4cc5e410de3b2ff264
Security Audit — socket — ulw-loop