cruise-control

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly consistent with its stated purpose as an automatic StackShift orchestrator, but its footprint is high-impact. The main concern is unattended repo-wide analysis plus automatic file generation and implementation, with indirect prompt-injection risk from untrusted project content and some extended trust in downstream tooling. No clear evidence of credential theft, covert exfiltration, obfuscation, or malicious install behavior was found.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:16 PM
Package URL
pkg:socket/skills-sh/jschulte%2Fclaude-plugins%2Fcruise-control%2F@39389e4a6a7ab75513ed89462ca3c486826b2069