mise-tasks
Warn
Audited by Socket on Sep 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core mise task guidance is mostly legitimate, but the skill's footprint expands into autonomous repository bootstrapping, cross-skill installation/invocation, credential-bearing release automation, and public GitHub actions. Data flows mostly target official tools, so this is not confirmed malware, but the scope is broader and riskier than the stated purpose.
Confidence: 90%Severity: 74%
Audit Metadata