comet-build

Warn

Audited by Socket on May 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: mostly coherent for a build-orchestration skill, but the required transitive loading of multiple other skills and execution of repo-configured commands expands trust beyond this skill itself. No direct credential theft or off-platform exfiltration is present, so this looks like a moderate workflow/supply-chain risk rather than malware.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
May 29, 2026, 11:24 AM
Package URL
pkg:socket/skills-sh/rpamis%2Fcomet%2Fcomet-build%2F@c3a504c2f695232f2dfc68915e46e1389d43209e
Security Audit — socket — comet-build