why

Warn

Audited by Socket on Sep 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities are mostly coherent: cross-repository and cross-tool historical research reasonably involves git, GitHub, tickets, docs, chat, observability, and analytics. However, it broadens access by defaulting to all available MCPs, instructs non-readonly agent mode despite a research-only task, and sends code/context into whichever MCP servers are configured without verifying their trust boundary. This looks like an expansive enterprise investigation skill rather than malware, but it carries meaningful security risk from breadth, external MCP trust, and prompt-injection surface.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
Sep 7, 2026, 10:50 PM
Package URL
pkg:socket/skills-sh/michael-denyer%2Fpstack-claude%2Fwhy%2F@9e4f4cca94f9bcb7dffe2547172df1d04df59dfa4b30037b7abc2fe9077298df
Security Audit — socket — why