work-item-delivery-loop

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s behavior mostly matches its stated purpose, but it enables autonomous code changes and task-system write-back while depending on an unpinned third-party MCP bridge (`mcp-remote`) that likely handles authentication en route to One Horizon. Data flows are broadly consistent with the product, so this is not confirmed malware, but the combination of third-party credential mediation, untrusted task-content ingestion, and write/exec authority makes it a medium-high security risk.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
May 11, 2026, 12:01 PM
Package URL
pkg:socket/skills-sh/onehorizonai%2Fskills%2Fwork-item-delivery-loop%2F@89e2d80fe04162fb88f94994a065849d66df2d52