landing-report

Warn

Audited by Socket on May 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The advertised function is a read-only landing report, but the actual skill bundles telemetry, local state writes, artifact sync, prompt-driven configuration changes, and even possible repo mutations. The mismatch between stated purpose and real footprint is the main risk; this looks more like a gstack control-plane wrapper than a narrow dashboard skill.

Confidence: 90%Severity: 72%
Audit Metadata
Analyzed At
May 10, 2026, 12:20 PM
Package URL
pkg:socket/skills-sh/garrytan%2Fgstack%2Flanding-report%2F@76aabbfb5007db38601de79b651b4afde6e45508