retro
Warn
Audited by Socket on Jul 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The retrospective behavior is mostly aligned with the stated purpose, and there is no clear credential harvesting or malicious exfiltration in the skill text. However, it relies on same-org local helper binaries with no verifiable release/signing trail, performs substantial preamble execution, and forwards usage events through publisher tooling, which makes the install/execution trust footprint larger than a simple git-analysis skill.
Confidence: 84%Severity: 72%
Audit Metadata