dev

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: mostly coherent as a development workflow skill, with no credential harvesting or off-platform data exfiltration visible. Main risks are transitive local skill loading, Bash availability, and a local hook script executed via uv before edits; these are broader than a simple planning skill but still plausibly related to the workflow.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 27, 2026, 08:07 AM
Package URL
pkg:socket/skills-sh/edwinhu%2Fworkflows%2Fdev%2F@98d77747fc5995400c6a3bae668b06f6ebfa473e