candango-executor

Warn

Audited by Socket on May 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core behavior is coherent for autonomous feature delivery, but it grants substantial autonomous repo modification and command-execution capability, and it chains into additional custom skills with incomplete provenance. No clear malware or credential-harvesting behavior is visible, yet the autonomy and transitive trust make it medium risk.

Confidence: 80%Severity: 56%
Audit Metadata
Analyzed At
May 26, 2026, 03:33 PM
Package URL
pkg:socket/skills-sh/lucasbayma%2Fskills%2Fcandango-executor%2F@73fc836140ca7b2afc6f5ee541a15c6003ad5311
Security Audit — socket — candango-executor