canary

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core canary behavior is coherent and mostly read-only, and the Bun installer evidence looks same-org/official rather than a random payload. But this skill's actual footprint is much broader than post-deploy monitoring: large preamble execution, helper-binary delegation, telemetry/artifact-sync paths, and optional project-file mutation/commits. That makes the skill internally over-scoped for its stated purpose, though not clearly malicious.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
May 11, 2026, 08:10 PM
Package URL
pkg:socket/skills-sh/garrytan%2Fgstack%2Fcanary%2F@95211c20be6166b1dbf4290c818bf850d2d04b19