deliver-task

Warn

Audited by Socket on Aug 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities are largely coherent with a repository-local delivery orchestrator, and no credential exfiltration or third-party API routing is visible. The main issue is install/execution trust: it requires at least one unverifiable local CLI (`generate-task-contract`) and references another unverifiable tool (`deep-rules-review`) without source or release provenance in the provided evidence, which makes the workflow higher-risk even though it is not clearly malicious.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Aug 31, 2026, 05:42 AM
Package URL
pkg:socket/skills-sh/qianchengjie%2Fskills%2Fdeliver-task%2F@f06812f3d3bb63ab378ebc026c16a02068c5c09328f6e34f8dc9ef516e345560
Security Audit — socket — deliver-task