fleet
Warn
Audited by Socket on Apr 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's purpose mostly matches its behavior, and its only external API target is Linear's official endpoint, but it depends on launching an unverified, unpinned `npx` package that becomes a trusted local control plane. That supply-chain uncertainty, combined with broad multi-agent orchestration capability, makes the skill medium-high risk even without clear evidence of credential theft or exfiltration.
Confidence: 82%Severity: 78%
Audit Metadata