thread
Warn
Audited by Socket on Aug 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s core behavior matches its stated purpose, and Herdr provenance looks legitimate, so it is not outright malicious. However, it deliberately spawns secondary agents in auto mode, can create worktrees and run external harness binaries from local config, and wires cross-pane prompting/callbacks; that makes the security footprint high for an agent skill even though it is internally coherent.
Confidence: 89%Severity: 74%
Audit Metadata