feature
Warn
Audited by Socket on May 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is coherent as an autonomous feature-delivery orchestrator, but its footprint is high-impact: it intentionally bypasses user checkpoints, runs multiple local helper scripts, and can commit/publish changes through /ship. This is better classified as suspicious/high-risk automation than malware because the behavior matches the stated purpose, yet the autonomous side effects and unverified local helper trust materially raise risk.
Confidence: 84%Severity: 62%
Audit Metadata