tailrocks-skill-create

Warn

Audited by Socket on Sep 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose and repository-writing behavior are broadly coherent, and there is no sign of credential theft or exfiltration. The main concern is install/execution trust: it depends on external CLIs and an unbundled scaffolder executable at `<installed-skill-path>` whose source and release provenance are not verifiable from the provided skill, which makes the mutation path a medium-high supply-chain risk.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Sep 8, 2026, 03:13 PM
Package URL
pkg:socket/skills-sh/tailrocks%2Ftailrocks-skill-authoring-skills%2Ftailrocks-skill-create%2F@a06b74252e462274811d72a155483d6e3cab6bb6437e357865b882b2476fbd8a
Security Audit — socket — tailrocks-skill-create