struere-developer

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose largely matches its capabilities, but it grants an AI agent authority to fetch untrusted external docs, modify code, manage platform keys, and automatically sync/deploy without per-action approval. The main issues are autonomy and remote-content influence, plus moderate install trust uncertainty around the Struere CLI/package; there is no strong evidence of credential theft or covert exfiltration.

Confidence: 81%Severity: 59%
Audit Metadata
Analyzed At
May 7, 2026, 11:57 PM
Package URL
pkg:socket/skills-sh/MarcoNaik%2Fstruere-skill%2Fstruere-developer%2F@26a8dde4baf824350880778538acc1ff5fc212d0