comet-hotfix

Warn

Audited by Socket on Jun 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is coherent for a bug-fix workflow, but its trust model is weak. It executes a locally discovered shell script, automatically performs code changes and commits, and depends on multiple transitive skill loads. No clear credential theft or external exfiltration is present, so this is not confirmed malware, but it carries medium security risk.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 13, 2026, 12:56 AM
Package URL
pkg:socket/skills-sh/rpamis%2Fcomet%2Fcomet-hotfix%2F@6f59094eea4503a79dea2cf14febff0b059ef3c4
Security Audit — socket — comet-hotfix