recipe-fullstack-implement

Warn

Audited by Socket on Sep 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the recipe is purpose-aligned as an orchestrator, but its main risk is transitive trust. It instructs the agent to execute multiple unpinned skills/subagents, then make impactful repo changes including commits and task-file deletion. No confirmed credential theft or explicit exfiltration is present, so this is not malware, but it is a medium-high risk orchestration skill due to autonomy and dependency chaining.

Confidence: 83%Severity: 69%
Audit Metadata
Analyzed At
Sep 23, 2026, 10:10 AM
Package URL
pkg:socket/skills-sh/shinpr%2Fclaude-code-workflows%2Frecipe-fullstack-implement%2F@fc2be8ef20022ea458333a3433297aac4566fdc25bb38da5bbed23eadeaf84e6
Security Audit — socket — recipe-fullstack-implement