finish-task

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core workflow is coherent for a developer productivity skill, but it depends on a non-official third-party Linear CLI and routes Linear-authenticated actions through that tool. GitLab usage is consistent and official, and actions are user-confirmed, so this is not clearly malicious; the main concern is proportionate but real supply-chain and credential-forwarding risk from the Linear integration.

Confidence: 89%Severity: 64%
Audit Metadata
Analyzed At
Apr 6, 2026, 08:17 AM
Package URL
pkg:socket/skills-sh/seangjr%2Fproduct-skills%2Ffinish-task%2F@067de27a134645ded8815ef9d4a5441753a0e6e9
Security Audit — socket — finish-task