step-running
Warn
Audited by Socket on May 11, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is mostly aligned with its stated purpose and lacks external installs, credential collection, or clear exfiltration. However, autonomous background execution plus local command running from plan content and an unseen hook script create meaningful integrity risk, especially if plan files are not trusted.
Confidence: 100%Severity: 60%
Audit Metadata