task

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core planning behavior is coherent and mostly local, but the auto mode materially expands scope by autonomously spawning downstream skills, creating transitive trust and real-world project actions beyond simple task drafting. Install trust is not overtly hostile, yet publisher/provenance is not fully clean due to repo-name mismatch. No credential harvesting or direct exfiltration is evident.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Mar 24, 2026, 02:06 AM
Package URL
pkg:socket/skills-sh/webriq%2Fclaude-skills%2Ftask%2F@3de2bfa2730a54789087a1fb7b1838d9feddb9d9