recipe-build

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly consistent with an internal repo-task orchestrator, but its autonomous multi-step execution, commit authority, dependence on other skills, and ability to act on task/design content create medium risk. No clear credential theft, exfiltration, malicious installer, or incompatible capability is present, so this is not malicious; the main concerns are transitive trust and autonomous write/commit behavior.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 9, 2026, 10:41 PM
Package URL
pkg:socket/skills-sh/shinpr%2Fclaude-code-workflows%2Frecipe-build%2F@c716b48034ddd067680b74de257baab0a994b6ee