start-task

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core task-management purpose is coherent, but the skill expands trust by loading additional skills from task data and invoking unverifiable local/internal tooling and hooks. No clear credential theft or overt exfiltration is shown, yet the transitive skill-loading and opaque local dependencies make the overall footprint higher risk than a simple task helper.

Confidence: 83%Severity: 72%
Audit Metadata
Analyzed At
Mar 29, 2026, 08:41 AM
Package URL
pkg:socket/skills-sh/Jamie-BitFlight%2Fclaude_skills%2Fstart-task%2F@8843ea18b34e5439c6382c9ec3322f65518f2576
Security Audit — socket — start-task