ss-coding

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is purpose-aligned for orchestrated coding and does not show credential theft, covert exfiltration, or malicious payload delivery. Main risks are transitive trust in sibling skills, autonomous repo-changing behavior, and indirect prompt injection from external requirement documents or repo-authored commands, so this is best classified as SUSPICIOUS rather than malicious.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Aug 26, 2026, 05:56 PM
Package URL
pkg:socket/skills-sh/lbk-open%2Fsuper-spec%2Fss-coding%2F@7490500575b6170666b87cba664d8c33659d845798815db3a41ea00a31a29fda
Security Audit — socket — ss-coding