do-execute-bugfix

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core bug-fix capabilities are mostly aligned with the stated purpose, but the skill meaningfully increases risk through mandatory autonomous execution, local command/script execution, automatic service startup, and dependence on preconfigured MCP servers that may route data externally (notably Context7). This is not fundamentally incompatible with a bug-fix skill, so it is not malicious, but it has medium security risk because it can act broadly without per-action approval and can expose project/app context to external MCP infrastructure.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 6, 2026, 12:43 AM
Package URL
pkg:socket/skills-sh/fabio-barboza%2Fdevelopment-orchestrator%2Fdo-execute-bugfix%2F@7497d2e0d3b1ba281af962c24a2a5ccbb06d9913
Security Audit — socket — do-execute-bugfix