landing-report
Warn
Audited by Socket on May 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The advertised function is a read-only landing report, but the actual skill bundles telemetry, local state writes, artifact sync, prompt-driven configuration changes, and even possible repo mutations. The mismatch between stated purpose and real footprint is the main risk; this looks more like a gstack control-plane wrapper than a narrow dashboard skill.
Confidence: 90%Severity: 72%
Audit Metadata