lfg

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose matches its software-delivery capabilities, and visible data flows stay on local git/GitHub surfaces, but it grants broad autonomous real-world actions and relies on unverifiable transitive skills. The main risk is not overt malware or credential theft in this snippet; it is high-impact autopilot behavior plus trust expansion to other skills and untrusted CI/review content.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
May 8, 2026, 05:55 AM
Package URL
pkg:socket/skills-sh/EveryInc%2Fcompound-engineering-plugin%2Flfg%2F@2824663963dc4b73149b0df0a5dd07f67032dad9