cdd-master-chef

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is coherent with its stated purpose, but that purpose is inherently high-impact because it lets the agent autonomously modify, commit, and push code through a persistent multi-step control loop and subagents. I see no clear credential theft, covert exfiltration, or malicious mismatch, so this is not malware; the main concern is operational and security risk from autonomous real-world actions and transitive trust in other cdd-* skills.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 18, 2026, 07:40 AM
Package URL
pkg:socket/skills-sh/ruphware%2Fcdd-skills%2Fcdd-master-chef%2F@ef7de754521fa53296db1c64bd70cb40ef71c3d4