consult-brd-writer
Warn
Audited by Socket on Sep 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the business workflow is internally consistent and the requested Google Drive/Docs/CRM actions fit the stated BRD/PRD-writing purpose, with explicit gating before client-facing actions. The main security issue is transitive trust: it tells the agent to install a skill from a GitHub repository via the skills CLI, which extends trust to external instructions and should be treated as a medium-risk supply-chain dependency.
Confidence: 86%Severity: 56%
Audit Metadata