onboarding-cro
Warn
Audited by Socket on Aug 27, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core onboarding advice is benign, but the skill’s actual footprint is broader than its stated CRO purpose: it mandates external tooling, persistent memory, issue-tracker/process integration, and untrusted-content handling with possible write/exec paths. No direct malware or credential-harvesting behavior is evident, but scope creep and third-party tool routing make it a medium-risk skill.
Confidence: 84%Severity: 56%
Audit Metadata