to-prd
Warn
Audited by Socket on May 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The main PRD-generation behavior aligns with the stated purpose, but the undocumented `/setup-leandrocfe-skills` command creates install-trust uncertainty, and the skill performs autonomous external publication to the issue tracker. No clear evidence of malware or credential theft is present, but supply-chain and workflow-write risks make it higher than benign.
Confidence: 80%Severity: 61%
Audit Metadata