dstack-beads-adopt-feature
Warn
Audited by Socket on Aug 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the workflow purpose is coherent, but the skill’s trust anchor is a repo-local dstack executable whose provenance cannot be verified from public evidence. There is no clear credential harvesting or malicious exfiltration, yet executing an unverified local CLI that performs backend mutations creates high supply-chain risk disproportionate to the available provenance.
Confidence: 84%Severity: 78%
Audit Metadata