slfg

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Suspicious. The skill’s purpose matches an orchestration workflow, but its footprint is broad and highly autonomous: it chains unreviewed skills, launches parallel subagents, mutates the repo, and updates a PR without pause. The main risk is not credential theft or malware, but unchecked transitive trust and autonomous action scope that exceed a narrowly bounded helper workflow.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Apr 2, 2026, 03:06 PM
Package URL
pkg:socket/skills-sh/marcusrbrown%2Fsystematic%2Fslfg%2F@f6f52719e8ce9ef5a19bbcdb8cc50cc489b033ae
Security Audit — socket — slfg