tdd-repair

Warn

Audited by Socket on Jun 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent for automated test-driven repair and uses the official Claude CLI, so it is not strong evidence of malware. However, it grants a nested agent Bash+Edit capability over untrusted repo content and executes caller-supplied test commands, creating meaningful code-execution and prompt-injection risk that is disproportionate for untrusted projects.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Jun 22, 2026, 10:23 PM
Package URL
pkg:socket/skills-sh/ruvnet%2Fruflo%2Ftdd-repair%2F@d95e46716aa4dbf7ce0d1d2320104fc8dba094551eadb8b5dbf5e285786487fd
Security Audit — socket — tdd-repair