recipe-implement

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly consistent with an implementation orchestrator, but it grants substantial delegated power to unspecified subagents and a community skill without provenance or version guarantees. There is no clear credential theft, exfiltration, or malicious payload behavior; the main risk is transitive trust plus semi-autonomous codebase actions like commits and cleanup.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
May 9, 2026, 10:41 PM
Package URL
pkg:socket/skills-sh/shinpr%2Fclaude-code-workflows%2Frecipe-implement%2F@6aec13e1ce57214c9cb9414b8058b06287a37cce