retro

Warn

Audited by Socket on May 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The retrospective functionality itself is plausible and mostly benign, and the helper binaries appear same-org and officially distributed. But this skill’s real footprint is much broader than a report generator: it can sync artifacts remotely, send telemetry, edit CLAUDE.md, migrate vendored installs, and create git commits. That makes the skill internally over-scoped for its stated purpose, with medium security risk but low evidence of deliberate malware.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
May 14, 2026, 12:30 PM
Package URL
pkg:socket/skills-sh/garrytan%2Fgstack%2Fretro%2F@72a5b2abca7275d892fcc95929619b35857d3638