squad-run

Warn

Audited by Socket on Jun 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's orchestration behavior broadly matches its stated purpose, but it has a wide operational footprint: networked task-state control, subagent dispatch, local code modification, and automatic git commits. The main concerns are unpinned API destination trust ($BASE_URL), broad repo-wide commit behavior, and optional autonomous progression, not clear malware or credential theft.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 13, 2026, 01:39 PM
Package URL
pkg:socket/skills-sh/steloit%2Fsquad-skills%2Fsquad-run%2F@fa3f72e8046607cf3c28334b74c72b74a3af257127fca8e335e8e1a1f72a71fc
Security Audit — socket — squad-run