greeting-checkin

Warn

Audited by Socket on May 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is a lightweight greeting check-in, but the actual footprint includes executing maintenance actions from announcement files, silently staging/committing changes, and acting without per-action approval. The main risk is autonomous command execution and repo mutation driven by content, not external supply-chain or explicit credential exfiltration.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
May 11, 2026, 12:54 PM
Package URL
pkg:socket/skills-sh/fabioc-aloha%2FPBI-Visual-Assistant%2Fgreeting-checkin%2F@6923bef76dccb092807cea61089a15d994621e72