logic-master
Warn
Audited by Socket on Aug 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is purpose-aligned and uses an official OpenAI CLI, so it is not inherently malicious. The main issue is proportionality: it mandates `--yolo` auto-approval for all tasks, giving an external CLI broad unsupervised execution and allowing project files/images to flow off-machine. Trust is same-org and documented, which keeps this below high supply-chain concern, but the autonomy and external data flow make it medium risk overall.
Confidence: 88%Severity: 64%
Audit Metadata