slfg

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the wrapper’s purpose matches an engineering orchestration skill, but its autonomy is disproportionate because it mandates uninterrupted multi-agent execution through code changes, testing, and PR updates. Install provenance for the referenced main plugin looks reasonably consistent, so the primary risk is autonomous action and delegated trust to downstream skills rather than confirmed malware or credential theft.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
Mar 27, 2026, 05:27 PM
Package URL
pkg:socket/skills-sh/udecode%2Fplate%2Fslfg%2F@40d601e077211a7c82895e9b4316aa61d537b38d
Security Audit — socket — slfg