god

Warn

Audited by Socket on May 16, 2026

3 alerts found:

Anomalyx3
AnomalyLOW
sub-skills/spec/SKILL.md

SUSPICIOUS. A skill é majoritariamente coerente com o objetivo de produzir specs e usa integrações oficiais esperadas, sem cadeia clara de download-execute. O principal risco vem de hooks em linguagem natural, publicação externa opcional e delegação a outras sub-skills não fornecidas, o que amplia ações e fluxos de dados além de uma simples skill documental.

Confidence: 82%Severity: 56%
AnomalyLOW
sub-skills/pack-up/SKILL.md

SUSPICIOUS: the core git/PR automation is consistent with the stated purpose and uses official GitHub tooling, but the skill is high-impact because it executes repo-defined natural-language hooks and performs autonomous external actions like push/PR creation. Risk comes from hook execution and broad agent capabilities rather than overt malware or suspicious supply-chain behavior.

Confidence: 88%Severity: 69%
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s core capabilities broadly match its stated purpose as a development workflow orchestrator, and the visible execution path relies on local scripts and official tooling rather than unverifiable binaries. Risk is elevated by broad agent permissions, hook-driven arbitrary instructions, external publishing targets, and ingestion of untrusted Jira/Figma content while retaining write/exec powers. This looks coherent but high-trust; use only with explicit user approval for outbound publishing and git/PR actions.

Confidence: 82%Severity: 59%
Audit Metadata
Analyzed At
May 16, 2026, 11:25 AM
Package URL
pkg:socket/skills-sh/davidsgoncalves%2Fgoal-driven-development%2Fgod%2F@b04714be97a78610fd6745bcdd0b979c1b122228