investigate

Warn

Audited by Socket on Aug 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core debugging purpose is plausible, but the actual footprint is much broader: it runs many external helper binaries, reads/writes persistent user state, can modify repo governance files, perform commits, and optionally send telemetry or sync artifacts remotely. This looks more like a general gstack orchestration layer than a narrowly scoped investigation skill, so the capability and data-flow scope are disproportionate to the stated purpose.

Confidence: 79%Severity: 72%
Audit Metadata
Analyzed At
Aug 7, 2026, 08:38 PM
Package URL
pkg:socket/skills-sh/kunchenguid%2Fprogrambench-bench%2Finvestigate%2F@475ec7b9b5fc818f386a6a457b86cfc17a4a872a5adac13bf40fbbe268f68388
Security Audit — socket — investigate