phase

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose largely matches its engineering-orchestration capabilities, and it includes explicit user approvals between major phases. Risk comes from broad autonomous code execution through Bash and parallel subagents, plus reliance on a Sugar CLI/orchestrator path whose official provenance was not verified from the supplied evidence. No clear credential theft or exfiltration is shown, so this is not confirmed malware, but it is a medium-risk automation skill with partial supply-chain uncertainty.

Confidence: 82%Severity: 61%
Audit Metadata
Analyzed At
Apr 13, 2026, 09:34 PM
Package URL
pkg:socket/skills-sh/scando1993%2Fsugar%2Fphase%2F@0a4868013137792c270d57073a86e631cfd09f31