cruise-control
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is broadly consistent with its stated purpose as an automatic StackShift orchestrator, but its footprint is high-impact. The main concern is unattended repo-wide analysis plus automatic file generation and implementation, with indirect prompt-injection risk from untrusted project content and some extended trust in downstream tooling. No clear evidence of credential theft, covert exfiltration, obfuscation, or malicious install behavior was found.
Confidence: 84%Severity: 68%
Audit Metadata