develop-issue
Warn
Audited by Socket on May 26, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the workflow purpose is coherent, but it materially expands trust by instructing installation of multiple external child skills via a mutable CLI/version path and default-branch references. This is more a transitive supply-chain and prompt-surface risk than confirmed malicious behavior.
Confidence: 100%Severity: 60%
Audit Metadata