build
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
Suspicious rather than malicious: the skill’s purpose matches workflow orchestration, but its footprint is broad because it delegates to many other skills, processes untrusted repository/agent content, and can commit or update PRs. Main risks are autonomy and transitive trust, not credential theft or covert exfiltration.
Confidence: 80%Severity: 63%
Audit Metadata