standup

Warn

Audited by Socket on Jul 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent and the visible data flow appears local-only, but the skill executes an unprovided local script at load time using pre-execution syntax. There is no evidence of credential theft or outbound exfiltration in the supplied text, yet the hidden script dependency and automatic execution make the skill higher risk than a normal documentation-only skill.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Jul 16, 2026, 03:50 PM
Package URL
pkg:socket/skills-sh/karanb192%2Fclaude-code-hooks%2Fstandup%2F@d70aa4d3ae681deb7c70f33fb5445319f9b1a7443d29e946a380e4658d3f4740
Security Audit — socket — standup