resolve-todo-parallel

Warn

Audited by Socket on Mar 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly coherent for repo todo maintenance, and there is no clear credential harvesting or malicious exfiltration path. Risk comes from autonomous parallel subagents, transitive skill use, and automatic commit/push/delete actions based on untrusted todo content.

Confidence: 81%Severity: 62%
Audit Metadata
Analyzed At
Mar 22, 2026, 11:27 PM
Package URL
pkg:socket/skills-sh/EveryInc%2Fcompound-engineering-plugin%2Fresolve-todo-parallel%2F@8f5d04c038f2a6d5d1933c44fd6c6065566dc1b5