prd

Warn

Audited by Socket on May 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core behavior matches the stated PRD-and-issue-planning purpose, and GitHub/local modes are broadly proportionate. The main concern is the optional Baidu iCafe mode, which requires an externally authenticated CLI with no clearly verifiable public provenance, creating a credential-forwarding and supply-chain risk disproportionate to an otherwise documentation-oriented skill.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
May 16, 2026, 08:50 AM
Package URL
pkg:socket/skills-sh/smallnest%2Fgoal-workflow%2Fprd%2F@c146b696f7957d763ce50354c9327fb5250eb4ed
Security Audit — socket — prd