work

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core workflow is plausible for a project-execution skill, but its actual footprint is broader than necessary because it grants powerful write/exec capabilities and, most importantly, dynamically loads additional skills from prd.json content. No clear credential theft or exfiltration is present, but the transitive skill-loading and autonomous commit behavior make this a high-trust skill that should be treated cautiously.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
Mar 29, 2026, 07:10 AM
Package URL
pkg:socket/skills-sh/somtougeh%2Fdotfiles%2Fwork%2F@1d19f3b6e7e6b8010028dac003872cd057f6c1d3
Security Audit — socket — work