pstack
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is mostly coherent with its stated purpose as an engineering workflow orchestrator, and its main external tools route to official GitHub/Cursor endpoints rather than a proxy. The key concern is proportionality of autonomy: it can coordinate long-running background work, force-push/rebase PR branches, post replies, and in some playbooks merge PRs with limited human involvement. That is not clearly malicious, but it is high-impact and should be treated as a risky orchestration skill rather than a benign documentation-only skill.
Confidence: 88%Severity: 74%
Audit Metadata