develop

Warn

Audited by Socket on Aug 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s workflow purpose is coherent, but it materially expands trust by instructing the agent to install and rely on multiple remote child skills, including third-party GitHub sources, with mutable version selection. No direct credential theft or exfiltration is evident, but transitive skill installation plus autonomous repo actions makes this medium-to-high risk.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Aug 28, 2026, 09:35 AM
Package URL
pkg:socket/skills-sh/patinaproject%2Fskills%2Fdevelop%2F@88c085fef5c27d97ee2c9f017d0d5aa0b839f2c1914327f77b0185d79bb20e0f
Security Audit — socket — develop