investigate

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core debugging workflow is legitimate, but the skill's actual footprint is much broader than 'investigate a bug': it runs many local binaries, persists state, can modify project routing files and commit changes, and supports optional telemetry/artifact sync with unspecified external endpoints. This looks more like a full gstack platform bootstrap/orchestration layer than a narrowly scoped investigate skill, so the mismatch and install-trust ambiguity raise medium risk rather than confirming malware.

Confidence: 79%Severity: 58%
Audit Metadata
Analyzed At
May 16, 2026, 12:53 PM
Package URL
pkg:socket/skills-sh/garrytan%2Fgstack%2Finvestigate%2F@ce5785ffa31378b973946de6606584a389224fd0
Security Audit — socket — investigate