full-deploy

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's overall purpose is plausible, but its footprint is too autonomous and trust-expanding. The main risks are transitive delegation to other skills, deployment-capable actions without user confirmation, and silent local telemetry writes. No clear credential theft or malicious exfiltration is present, but the skill is not well-scoped for safe unattended use.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Mar 23, 2026, 11:03 AM
Package URL
pkg:socket/skills-sh/tinh2%2Fskills-hub-registry%2Ffull-deploy%2F@48a524ffa1e0207d749819f225a30e44c5b149cf
Security Audit — socket — full-deploy