compliance-gate
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s compliance purpose broadly matches its scanning/remediation workflow, but it grants an AI agent high-risk autonomous behavior: offensive security testing, automatic code changes, dependency updates, and git commits without user confirmation. No direct exfiltration or clear malware appears in this file, yet the transitive trust in unseen local skills and autonomous pentest/remediation make the overall security risk high.
Confidence: 86%Severity: 74%
Audit Metadata