slopship
Warn
Audited by Socket on Aug 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s stated purpose and command set are internally coherent, and it avoids embedded installers, but its core behavior depends on an unverified external slopshipper binary and optional reviewer tools with unresolved provenance. That makes the install/execution trust footprint disproportionate unless the operator independently verifies the CLI source and release chain.
Confidence: 84%Severity: 78%
Audit Metadata