plan-fix
Warn
Audited by Socket on Apr 7, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s purpose mostly matches its capabilities, but it lets the agent ingest external analysis, clone an unspecified repo, execute repo-controlled builds, patch a product pack, and start services based on missing CLAUDE.md instructions. This is a coherent engineering workflow, not clear malware, yet the unresolved trust chain and execute-on-untrusted-content pattern create medium security risk.
Confidence: 82%Severity: 60%
Audit Metadata