dx
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core audit behavior is coherent and uses only local project files, but the skill overreaches by forcing autonomous execution, automatically invoking other skills under --fix, and silently writing telemetry outside the repository. No strong malware or credential-theft signals are present, but the transitive trust chain and autonomous file-changing behavior make it higher risk than a normal audit skill.
Confidence: 89%Severity: 74%
Audit Metadata