triage
Warn
Audited by Socket on Jun 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core capabilities fit a triage skill and the main network targets are expected, but risk is elevated by load-time script execution, broad write/agent permissions, untrusted backlog content being processed with action-capable tools, and transitive trust in third-party `superpowers` skills. I see no clear credential-harvesting or incompatible malicious behavior, so this is not malware, but it is a medium-risk workflow automation skill.
Confidence: 82%Severity: 56%
Audit Metadata