sandcastle

Warn

Audited by Socket on Aug 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill's core behavior is broadly consistent with its stated purpose, but it is high risk because it enables unattended code changes and public GitHub actions while forwarding CLAUDE and GitHub tokens into third-party orchestration tooling and sandboxed agent workflows. This looks more suspicious than benign from a security perspective due to autonomy and credential exposure, though the provided content does not show clear malware, exfiltration, or deceptive behavior.

Confidence: 82%Severity: 78%
Audit Metadata
Analyzed At
Aug 2, 2026, 09:46 AM
Package URL
pkg:socket/skills-sh/will-ness-ai%2Fskills%2Fsandcastle%2F@e60cc1fd3580bc3834b8949078b976f81e33529f1f3e42295785afa32f88bb43
Security Audit — socket — sandcastle