squad

Warn

Audited by Socket on Jun 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly aligned with task-board management, but it forwards auth tokens and project/task data to a configurable backend that is only visibly represented by a vercel.app deployment, with key auth/setup details hidden in referenced files not provided here. No malware indicators or remote installer behavior are present, but endpoint provenance and credential routing are insufficiently verifiable.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 13, 2026, 01:39 PM
Package URL
pkg:socket/skills-sh/steloit%2Fsquad-skills%2Fsquad%2F@5367406ee4ffbb2dab64b43b9354efec87937c2cbfe3d7bfe17627b2981f62e6
Security Audit — socket — squad