standup
Warn
Audited by Socket on Jul 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is coherent and the visible data flow appears local-only, but the skill executes an unprovided local script at load time using pre-execution syntax. There is no evidence of credential theft or outbound exfiltration in the supplied text, yet the hidden script dependency and automatic execution make the skill higher risk than a normal documentation-only skill.
Confidence: 88%Severity: 72%
Audit Metadata