st-execute-task
Warn
Audited by Socket on Jun 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core file and status-management behavior is coherent for a task executor, but the skill gives an internal agent broad implementation authority based on local markdown hooks/tasks, creating prompt-injection and autonomous-action risk. It also references an unverified `npx strikethroo init` setup path, which raises install-trust concerns even though no direct credential theft or overt exfiltration is shown.
Confidence: 100%Severity: 60%
Audit Metadata