todo-resolve

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly aligned with repository todo resolution, but it expands scope through parallel sub-agents, transitive loading of another skill, and autonomous git commit/push. No clear credential theft, exfiltration endpoint, or malicious installer is present; the main risk is broad repository modification and external publication actions without explicit per-action approval.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 28, 2026, 01:15 AM
Package URL
pkg:socket/skills-sh/EveryInc%2Fevery-marketplace%2Ftodo-resolve%2F@fb974c4d7d3ea4ef60b83b3062eea91b1eb7f99d