feature

Warn

Audited by Socket on May 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is coherent as an autonomous feature-delivery orchestrator, but its footprint is high-impact: it intentionally bypasses user checkpoints, runs multiple local helper scripts, and can commit/publish changes through /ship. This is better classified as suspicious/high-risk automation than malware because the behavior matches the stated purpose, yet the autonomous side effects and unverified local helper trust materially raise risk.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
May 14, 2026, 06:45 AM
Package URL
pkg:socket/skills-sh/garagon%2Fnanostack%2Ffeature%2F@b9eeaab37db341a1e5b9d0b9f75ed83c12e5feb4