feature-to-posts

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core purpose is benign and the file access is mostly proportionate, but the skill instructs the agent to load additional skills by ambiguous name from an ecosystem where the same skill name appears under multiple publishers. That transitive trust risk, combined with hard-coded local file reads, makes it riskier than a simple writing guide, though there is no evidence of credential theft, exfiltration endpoints, or autonomous posting.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Apr 13, 2026, 11:17 AM
Package URL
pkg:socket/skills-sh/marclelamy%2FSKILLS%2Ffeature-to-posts%2F@90289c946ebfb247e2db1db624f12849f2b64b4d
Security Audit — socket — feature-to-posts