cto-heartbeat

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core GitHub triage/dispatch behavior matches the stated purpose, and there is no notable installer or binary provenance issue. However, the skill reads raw PATs from a hard-coded local `.env` file and forwards another token plus report data to an undocumented localhost service, which makes the credential/data handling broader and less trustworthy than necessary for a backlog-management skill.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
Apr 22, 2026, 03:50 PM
Package URL
pkg:socket/skills-sh/fellowship-dev%2Fdogfooded-skills%2Fcto-heartbeat%2F@d22b7ee2fef815cd511e91f47380507b6b5e51f3