adr-driven-development
Warn
Audited by Socket on Aug 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s overall behavior is coherent with its claimed ADR-driven automation purpose, and I found no clear credential theft or malicious exfiltration. The main risk is transitive trust: it instructs installing and relying on additional GitHub-hosted skills and external agent CLIs, then uses them for unattended code-changing loops. That makes it high security risk but not confirmed malware.
Confidence: 86%Severity: 76%
Audit Metadata