health

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core health-check behavior is legitimate, but the actual skill footprint is much broader than its stated purpose: it runs many helper executables, writes local analytics/history, can modify project docs and git state, and may sync telemetry/artifacts remotely. Same-org gstack provenance reduces the chance of outright malware, but the scope is disproportionate for a code-quality dashboard.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
May 16, 2026, 12:52 PM
Package URL
pkg:socket/skills-sh/garrytan%2Fgstack%2Fhealth%2F@8e48c7c440b190cabdc2195891e18e90f147ef0a
Security Audit — socket — health