executing-single-task

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior is mostly coherent for a single-task execution skill and stays local to the repo, but the mandatory dependency on using-superpowers and possible additional skill loading introduces a transitive trust risk without clear provenance. No direct credential theft or exfiltration is evident, so this is not malware, but it carries medium security risk due to autonomous repo modification and external skill chaining.

Confidence: 80%Severity: 52%
Audit Metadata
Analyzed At
Mar 29, 2026, 09:22 PM
Package URL
pkg:socket/skills-sh/satone7%2Fskills%2Fexecuting-single-task%2F@c6137dfb3d146bab1daf7786d3c0ccb55e672c94