squad-run
Warn
Audited by Socket on Jun 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's orchestration behavior broadly matches its stated purpose, but it has a wide operational footprint: networked task-state control, subagent dispatch, local code modification, and automatic git commits. The main concerns are unpinned API destination trust ($BASE_URL), broad repo-wide commit behavior, and optional autonomous progression, not clear malware or credential theft.
Confidence: 100%Severity: 60%
Audit Metadata