st-execute-task

Warn

Audited by Socket on Jun 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core file and status-management behavior is coherent for a task executor, but the skill gives an internal agent broad implementation authority based on local markdown hooks/tasks, creating prompt-injection and autonomous-action risk. It also references an unverified `npx strikethroo init` setup path, which raises install-trust concerns even though no direct credential theft or overt exfiltration is shown.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 14, 2026, 02:12 PM
Package URL
pkg:socket/skills-sh/e0ipso%2Fstrikethroo%2Fst-execute-task%2F@d3492b176cf259d8aaa5c9549d72dd5554d998753fba7d2fb99c02db0829f906
Security Audit — socket — st-execute-task