absolute-human
Warn
Audited by Socket on Apr 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core SDLC automation behavior is largely coherent with the stated purpose and does not show credential theft or exfiltration, but the companion-check adds explicit transitive skill installation via `npx skills add`, expanding trust to additional skills and external package execution. Overall this is a legitimate engineering workflow skill with medium security risk due to transitive installation and broad autonomous repo actions, not confirmed malware.
Confidence: 87%Severity: 52%
Audit Metadata