typ-direct-work
Warn
Audited by Socket on Sep 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s behavior is largely coherent with a work-direction workflow and shows no credential harvesting, exfiltration, or stealth. However, it relies on an unidentified `ship` CLI with unverifiable provenance, which is disproportionate enough to keep overall risk high under the dependency-trust rules.
Confidence: 87%Severity: 72%
Audit Metadata