cleanup-health-inline
Warn
Audited by Socket on Jul 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The workflow is coherent for dead-code cleanup, and the verified Beads/pnpm tooling is not inherently malicious. However, the skill grants broad autonomous execution, includes automatic git push and Beads sync, and depends on unpinned subagents, making its operational scope and trust chain riskier than a narrowly scoped cleanup helper.
Confidence: 87%Severity: 74%
Audit Metadata