lfg

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's capabilities broadly match its purpose, but it enables autonomous external actions (commit/push/PR/CI handling) and relies on transitive child-skill trust. No direct malware or credential-harvesting behavior is evident in this skill alone, but the autonomy level makes it high operational risk.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Sep 16, 2026, 12:35 AM
Package URL
pkg:socket/skills-sh/everyinc%2Fcompound-engineering-plugin%2Flfg%2F@e97e80c2c28ab0552bbe61345da29a6a80a493d7e5903f393bf2541e28a79fda
Security Audit — socket — lfg