security-health-inline
Warn
Audited by Socket on Jul 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill’s purpose and capabilities are broadly aligned: it orchestrates vulnerability scanning, issue tracking, fixing, and verification. The main risk is not malware but scope: it can autonomously modify code, create/close remote issues, sync state, and push commits. Beads appears to be a legitimate official tool, but the referenced subagents are opaque from this skill text. Overall this is coherent but medium-risk due to autonomous external actions and partial trust-chain opacity.
Confidence: 87%Severity: 66%
Audit Metadata