phase-running
Warn
Audited by Socket on May 11, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s capabilities mostly match its stated purpose, but it grants a background sub-agent broad autonomous edit/execute behavior and runs verification commands sourced from plan content. No credential harvesting, external exfiltration, or suspicious installer is visible, so this is not malware, but it carries moderate operational risk.
Confidence: 100%Severity: 60%
Audit Metadata