groom-backlog-item

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core behavior mostly matches backlog grooming, but the skill grants broad autonomous research, command execution, and GitHub write/close actions, and it treats externally supplied procedural content as executable instructions. The largest trust concern is the unverified plugin_dh_backlog MCP dependency, which is entrusted with local backlog writes and GitHub synchronization.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Mar 29, 2026, 08:41 AM
Package URL
pkg:socket/skills-sh/Jamie-BitFlight%2Fclaude_skills%2Fgroom-backlog-item%2F@1edbff626edded8fd9ec5d454a49b7d12e1e5ec2