slfg
Warn
Audited by Socket on Apr 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Suspicious. The skill’s purpose matches an orchestration workflow, but its footprint is broad and highly autonomous: it chains unreviewed skills, launches parallel subagents, mutates the repo, and updates a PR without pause. The main risk is not credential theft or malware, but unchecked transitive trust and autonomous action scope that exceed a narrowly bounded helper workflow.
Confidence: 86%Severity: 74%
Audit Metadata