dstack-beads-implement-feature
Warn
Audited by Socket on Aug 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s stated purpose matches its task/commit workflow, but it relies on a local relative dstack binary whose provenance is not verifiable from the skill and whose exact subcommands are not publicly confirmed. No clear malware or credential theft is shown, yet the required black-box CLI and its authority over commits/task completion make the security risk high.
Confidence: 83%Severity: 78%
Audit Metadata