popsicle

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is mostly coherent with its stated documentation-audit purpose, but it carries meaningful risk from transitive skill installation, autonomous repeated git commits, and agent subprocess execution. No clear credential theft or covert exfiltration is present in the core workflow, so this is better classified as suspicious/high-risk automation than malicious.

Confidence: 82%Severity: 64%
Audit Metadata
Analyzed At
May 2, 2026, 05:45 PM
Package URL
pkg:socket/skills-sh/fellowship-dev%2Fdogfooded-skills%2Fpopsicle%2F@e8f65fa655a349899c4c96f28b1de55a431eb741
Security Audit — socket — popsicle