gdd

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the provided top-level skill is mostly coherent as a development-task orchestrator and shows no direct credential theft, exfiltration endpoint, or suspicious installer. However, it has broad execution authority, references missing sub-skills that likely contain the real operational logic, and implies autonomous git/PR actions without clear confirmation gates. Based on the file alone this is not malicious, but it carries medium security risk due to deferred trust and broad capabilities.

Confidence: 82%Severity: 51%
Audit Metadata
Analyzed At
Apr 14, 2026, 05:12 PM
Package URL
pkg:socket/skills-sh/davidsgoncalves%2Fgoal-driven-development%2Fgdd%2F@f4dba3645117ee2c665d65633254425cd84aec62