cso

Warn

Audited by Socket on May 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core audit purpose is legitimate and the gstack provenance appears same-org, so this is not confirmed malware. But the skill’s real footprint is much broader than a read-only security report: it reads outside-repo state, invokes bundled binaries, can modify project files and git history through shared framework flows, performs high-risk offensive-style security analysis, and may send telemetry/artifact data through helper binaries. High security risk, low-to-moderate evidence of malicious intent.

Confidence: 89%Severity: 81%
Audit Metadata
Analyzed At
May 11, 2026, 08:11 PM
Package URL
pkg:socket/skills-sh/garrytan%2Fgstack%2Fcso%2F@7d50d39b3f18d4a82960398fef72a8945cc08ce4