task-executor

Warn

Audited by Socket on Jul 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS-leaning but not malicious: the skill’s capabilities mostly fit its stated purpose, yet it has a broad orchestration footprint across trackers, repo writes, commits, external implementation engines, and other skills. The main concerns are transitive trust and indirect prompt-injection risk from ticket/spec content flowing into code-writing engines, plus autonomous ticket/comment/commit actions. No clear credential theft, covert behavior, malicious endpoint, or deceptive install path is present in the provided content.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Jul 15, 2026, 08:28 PM
Package URL
pkg:socket/skills-sh/OntoLedgy%2Fol_ai_context_library%2Ftask-executor%2F@ef68b63bb41560f72175f2565dab8a4eed43890a
Security Audit — socket — task-executor