task

Warn

Audited by Socket on May 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with its stated purpose and does not show clear malware or suspicious installer behavior, but it is high-impact orchestration: it reads untrusted tracker content, can edit/execute locally, loads additional skills, and by default performs public/external actions like PR creation and issue comments. Main risk is autonomy plus indirect prompt injection, not credential theft or covert exfiltration.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
May 14, 2026, 04:43 AM
Package URL
pkg:socket/skills-sh/udecode%2Fplate%2Ftask%2F@5fd94e2a201195fa349c3d7bfae0ece8e48d9740