hand-over-to-kiro

Warn

Audited by Socket on Jul 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is purpose-aligned and includes meaningful guardrails: no auto-install, no raw shell interpolation, scoped trust, and post-run diff verification. The main risk is structural: it requires a proprietary external CLI that can modify files and receive substantial repo context, so this is best classified as suspicious/high-risk from a supply-chain and delegated-agent perspective, not as confirmed malware.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
Jul 16, 2026, 10:13 AM
Package URL
pkg:socket/skills-sh/ulpi-io%2Fskills%2Fhand-over-to-kiro%2F@5a8290aa055eadd1d424d8cac40802813becc6d1ca2e9c200f887fc56ee8f04c
Security Audit — socket — hand-over-to-kiro