product-roadmap

Warn

Audited by Socket on Jul 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities are largely aligned, and its GitHub data flow is direct and proportionate. The main concern is install/execution trust: it requires unverifiable nks_* MCP tooling and implicitly trusts sibling skills without a verifiable publisher/source chain, which forces a high security-risk classification despite no clear signs of malware or credential theft.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Jul 7, 2026, 12:50 PM
Package URL
pkg:socket/skills-sh/verstak-ai%2Fskills%2Fproduct-roadmap%2F@c405eab9bf13439e75b3d63d0f9026bf1cbd86c955238fc756cafcfe83270d97
Security Audit — socket — product-roadmap