landing-report

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The narrow stated purpose is a read-only landing report, but the actual skill footprint is much broader: local state writes, telemetry, artifacts sync, optional browser opens, helper-driven eval/source, and branches that can modify project files or create commits. The core queue-report logic is coherent and the helper provenance appears same-org, so this is not confirmed malware, but the capability scope is disproportionate to a simple dashboard.

Confidence: 86%Severity: 61%
Audit Metadata
Analyzed At
May 16, 2026, 06:27 PM
Package URL
pkg:socket/skills-sh/garrytan%2Fgstack%2Flanding-report%2F@00f5b07e025d1d5538f8da5baa3662d0ff0ee89b
Security Audit — socket — landing-report