recipe-fullstack-implement
Warn
Audited by Socket on Sep 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the recipe is purpose-aligned as an orchestrator, but its main risk is transitive trust. It instructs the agent to execute multiple unpinned skills/subagents, then make impactful repo changes including commits and task-file deletion. No confirmed credential theft or explicit exfiltration is present, so this is not malware, but it is a medium-high risk orchestration skill due to autonomy and dependency chaining.
Confidence: 83%Severity: 69%
Audit Metadata