greeting-checkin
Warn
Audited by Socket on May 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is a lightweight greeting check-in, but the actual footprint includes executing maintenance actions from announcement files, silently staging/committing changes, and acting without per-action approval. The main risk is autonomous command execution and repo mutation driven by content, not external supply-chain or explicit credential exfiltration.
Confidence: 89%Severity: 82%
Audit Metadata