cs-build-audit-codebase
Warn
Audited by Socket on Aug 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is purpose-aligned for repository auditing, but it is high-trust operationally: it runs untrusted code, has broad shell/network capability, writes findings, and hands control to a second skill for project/task mutations. The CodeSpring CLI provenance appears consistent, so this is not confirmed malicious, but the combination of broad execution, untrusted-content processing, and transitive skill handoff makes it suspicious rather than benign.
Confidence: 83%Severity: 68%
Audit Metadata