post-patch-validation
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent and not overtly malicious, but it equips an AI agent to perform exploit-driven security validation and execute untrusted local code with broad local effects. Supply-chain trust is mostly acceptable, and data flows appear local-only, yet the offensive testing capability plus Bash/Workflow execution makes it high risk.
Confidence: 88%Severity: 72%
Audit Metadata