mise-tasks

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core mise task guidance is mostly legitimate, but the skill's footprint expands into autonomous repository bootstrapping, cross-skill installation/invocation, credential-bearing release automation, and public GitHub actions. Data flows mostly target official tools, so this is not confirmed malware, but the scope is broader and riskier than the stated purpose.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Sep 4, 2026, 06:58 AM
Package URL
pkg:socket/skills-sh/delorenj%2Fskills%2Fmise-tasks%2F@57f2ff79c73f1c75509ff0055ad3795e59e8a56b358e51968b7f0b90fab85709
Security Audit — socket — mise-tasks