project-builder
Warn
Audited by Socket on May 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core build/debug/scaffold behavior matches the stated engineering purpose, but the skill’s footprint is broadened by public publishing, scheduled task control, bash execution, and mandatory routing of API usage through an unverifiable intermediary proxy. The main concern is not overt malware but disproportionate capability and opaque data flow through third-party/internal infrastructure.
Confidence: 82%Severity: 63%
Audit Metadata