evolve

Warn

Audited by Socket on Sep 16, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior mostly matches a repo-automation/self-improvement skill, and the flagged installs are benign documentation examples. However, the skill's autonomous commit/merge/push capabilities, recurring self-update/version-check behavior, and same-publisher raw GitHub installer with no visible release verification make its trust footprint broader than ideal and medium risk overall.

Confidence: 86%Severity: 62%
AnomalyLOW
skill-creator/SKILL.md

SUSPICIOUS. The core workflow is coherent for a skill-creation assistant, but it extends beyond local drafting by instructing installation/loading of another third-party skill and enabling publication workflows. The main concern is transitive trust in personal GitHub skill repositories, not clear malware or credential theft.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:31 AM
Package URL
pkg:socket/skills-sh/miles990%2Fevolve-plugin%2Fevolve%2F@61eccdb87427eabbb5fb4d22ff63694abcc255445163f3a5d88ce593dc41e678
Security Audit — socket — evolve