product-prd

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent, but it grants an agent broad local execution and write authority through unverified repo-local commands, optional external MCP tooling, git commits, and follow-on skill activation. The footprint is somewhat disproportionate for a PRD-writing skill, mainly due to execution trust and autonomous state-changing actions, though there is no clear credential theft, exfiltration endpoint, or confirmed malicious payload.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Mar 27, 2026, 06:44 PM
Package URL
pkg:socket/skills-sh/jihunkim0%2Fjk-skills%2Fproduct-prd%2F@1d221f9f302aed70b3c54a424baab0961722e557