comet-verify

Warn

Audited by Socket on Jun 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core verification workflow is broadly aligned with its purpose, but it relies on broad local shell sourcing and mandatory transitive skill loading, including an ambiguously sourced external skill. The main risk is inherited trust and arbitrary local code execution during build/test and branch operations, not confirmed malware or direct credential theft.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 14, 2026, 08:04 AM
Package URL
pkg:socket/skills-sh/rpamis%2Fcomet%2Fcomet-verify%2F@d32d15e52e9efa77b571101aae2110f31be5b42fed42bbad940b249d7902f180
Security Audit — socket — comet-verify