full-deploy
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's overall purpose is plausible, but its footprint is too autonomous and trust-expanding. The main risks are transitive delegation to other skills, deployment-capable actions without user confirmation, and silent local telemetry writes. No clear credential theft or malicious exfiltration is present, but the skill is not well-scoped for safe unattended use.
Confidence: 88%Severity: 72%
Audit Metadata