comet-hotfix
Warn
Audited by Socket on Jun 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's purpose is coherent for a bug-fix workflow, but its trust model is weak. It executes a locally discovered shell script, automatically performs code changes and commits, and depends on multiple transitive skill loads. No clear credential theft or external exfiltration is present, so this is not confirmed malware, but it carries medium security risk.
Confidence: 100%Severity: 60%
Audit Metadata