recipe-implement
Warn
Audited by Socket on May 9, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is broadly consistent with an implementation orchestrator, but it grants substantial delegated power to unspecified subagents and a community skill without provenance or version guarantees. There is no clear credential theft, exfiltration, or malicious payload behavior; the main risk is transitive trust plus semi-autonomous codebase actions like commits and cleanup.
Confidence: 85%Severity: 56%
Audit Metadata