prd-generator

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The core PRD-generation behavior is benign and locally scoped, but the skill expands into mandatory git synchronization, commit, and push without per-action approval. Its main risk is autonomous publication to an arbitrary configured remote, plus optional execution of a repo-local script with unverified behavior.

Confidence: 89%Severity: 73%
Audit Metadata
Analyzed At
Apr 30, 2026, 05:47 PM
Package URL
pkg:socket/skills-sh/luongnv89%2Fskills%2Fprd-generator%2F@96723930822755a573109867376ae8672d583dfe
Security Audit — socket — prd-generator