daily-chief
Warn
Audited by Socket on Aug 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The workflow purpose is coherent, and the confirmation gate meaningfully limits abuse, but the skill outsources all auth and network activity to an unverified npm package executed via `npx`. Because that package handles bearer-token login and remote plan application without a verified publisher/source trail, the main risk is supply-chain trust and credential forwarding rather than confirmed malware.
Confidence: 79%Severity: 72%
Audit Metadata