iii-engine-config
Warn
Audited by Socket on Apr 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s main purpose is coherent and most capabilities fit engine configuration, but it includes installation/execution of external worker binaries with unclear registry provenance and automatic child-process spawning. Official same-project engine/docs evidence lowers concern for the core CLI/container path, yet the worker-install trust chain and unpinned Docker tag keep overall risk in the medium range.
Confidence: 82%Severity: 61%
Audit Metadata