god

Warn

Audited by Socket on May 13, 2026

1 alert found:

Anomaly
AnomalyLOW
sub-skills/pack-up/SKILL.md

SUSPICIOUS. The core commit/push/PR behavior fits the stated purpose of a pack-up skill, and data flows mostly align with GitHub/dev tooling. However, the skill grants broad execution and can autonomously perform external publishing actions, and its natural-language hooks materially expand scope by allowing arbitrary command execution from a local file. That makes it coherent but medium-risk rather than benign.

Confidence: 86%Severity: 61%
Audit Metadata
Analyzed At
May 13, 2026, 07:45 PM
Package URL
pkg:socket/skills-sh/davidsgoncalves%2Fgoal-oriented-development%2Fgod%2F@b854cfc6c61c087887ef0931c8a544017e3c635b